Skip to content
COOEY

EXPOSURES › CVE-2023-41990

CVE-2023-41990

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-01-08 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2023-41990 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 45/100 rceexploited-in-wildunpatched

Apple's iOS, iPadOS, macOS, tvOS, and watchOS contain a font-processing vulnerability enabling code execution.

This unspecified vulnerability allows attackers to execute arbitrary code by processing malicious font files across Apple's entire ecosystem, including devices used by defense contractors. DIB organizations must ensure all Apple devices are patched immediately to prevent unauthorized access and potential data exfiltration.

Shame score — While the vulnerability is actively exploited and affects multiple products, it is a known issue that Apple has disclosed and patched, making it less avoidable than negligent failures.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Apple iOS, iPadOS, macOS, tvOS, and watchOS contain an unspecified vulnerability that allows for code execution when processing a font file.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.