| VID |
50125 |
| Severity |
30 |
| Port |
3689 |
| Protocol |
TCP |
| Class |
SMB |
| Detailed Description |
The version of Apple iTunes running on the remote host is prior to 12.6.1. It is, therefore, affected by a remote code execution vulnerability due to memory corruption caused by improper validation of user-supplied input. An unauthenticated, remote attacker can exploit this, by convincing a user to open maliciously crafted web content, to execute arbitrary code.
* References: https://support.apple.com/en-us/HT207805 https://lists.apple.com/archives/security-announce/2017/May/msg00002.html
* Platforms Affected: Apple Computer, Inc., iTunes versions prior to 12.6.1 |
| Recommendation |
Upgrade to the latest version of iTunes (12.6.1 or later), available from the Apple Download Web site at http://www.apple.com/itunes/download/ |
| Related URL |
CVE-2017-6984 (CVE) |
| Related URL |
(SecurityFocus) |
| Related URL |
(ISS) |
|