Korean
<< Back
VID 50125
Severity 30
Port 3689
Protocol TCP
Class SMB
Detailed Description The version of Apple iTunes running on the remote host is prior to 12.6.1. It is, therefore, affected by a remote code execution vulnerability due to memory corruption caused by improper validation of user-supplied input. An unauthenticated, remote attacker can exploit this, by convincing a user to open maliciously crafted web content, to execute arbitrary code.

* References:
https://support.apple.com/en-us/HT207805
https://lists.apple.com/archives/security-announce/2017/May/msg00002.html
* Platforms Affected:
Apple Computer, Inc., iTunes versions prior to 12.6.1
Recommendation Upgrade to the latest version of iTunes (12.6.1 or later), available from the Apple Download Web site at http://www.apple.com/itunes/download/
Related URL CVE-2017-6984 (CVE)
Related URL (SecurityFocus)
Related URL (ISS)