peter bassill · operator
$ cve CVE-2017-2489 JSON

CVE-2017-2489 EXPLOIT

5.5
MEDIUM · CVSS 3.0 · EPSS 2.3% (pctl 83)

Patch early

A public exploit exists.

Description

An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "Intel Graphics Driver" component. It allows attackers to obtain sensitive information from kernel memory via a crafted app.

Scoring

CVSS5.5 (MEDIUM, v3.0)
VectorCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
EPSS2.31% — more likely to be exploited than 83% of all CVEs
WeaknessCWE-200
On CISA KEVno
Public exploityes
Published2017-04-02
Last modified2026-06-17

Affected (1)

VendorProduct
applemac os x

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD