← Back

CVE-2022-22582

nvd nist
Published: Feb 27, 2023Modified: Jun 17, 2026

JSON object

Loading...
5.5
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Exploitability: 1.8 / Impact: 3.6
Source: NVD

Description

A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. This issue is fixed in Security Update 2022-003 Catalina, macOS Big Sur 11.6.5, macOS Monterey 12.3. A local user may be able to write arbitrary files.

Affected (15)

Products: Apple: Mac Os X, Macos
2 products
Mac Os X
Macos
Configuration A
15 vulnerable
Vulnerable SoftwareAffected Versions
Apple
Version 10.15.7
Version 10.15.7 security_update_2020-001
Version 10.15.7 security_update_2020-005
Version 10.15.7 security_update_2020-007
Version 10.15.7 security_update_2020
Version 10.15.7 security_update_2021-001
Version 10.15.7 security_update_2021-002
Version 10.15.7 security_update_2021-003
Version 10.15.7 security_update_2021-006
Version 10.15.7 security_update_2021-007
Version 10.15.7 security_update_2021-008
Version 10.15.7 security_update_2022-001
Version 10.15.7 security_update_2022-002
Apple
From 11.0 to 11.6.5
From 12.0.0 to 12.3

References (6)

Source: product-security@apple.com
Release NotesVendor Advisory
Source: product-security@apple.com
Release NotesVendor Advisory
Source: product-security@apple.com
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesVendor Advisory

Timeline

No history available yet.