peter bassill · operator
$ cve CVE-2019-7287 JSON

CVE-2019-7287 KEV

7.8
HIGH · CVSS 3.1 · EPSS 4.6% (pctl 91)

Patch first

On CISA KEV — known exploited in the wild, due 2022-06-13.

Description

A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.1.4. An application may be able to execute arbitrary code with kernel privileges.

Scoring

CVSS7.8 (HIGH, v3.1)
VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS4.58% — more likely to be exploited than 91% of all CVEs
WeaknessCWE-787
On CISA KEVyes — remediate by 2022-06-13
Public exploitnone known
Published2019-12-18
Last modified2026-06-17

CISA KEV

NameApple iOS Memory Corruption Vulnerability
Added2022-05-23
Due2022-06-13
Vendor / productApple / iOS
Ransomware usenone reported

Affected (1)

VendorProduct
appleiphone os

References

→ the Explorer  ·  watch your stack  ·  NVD