CVE-2023-41993
high · 8.8Actively exploitedOn the CISA Known Exploited Vulnerabilities catalog
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Added 2023-09-25Remediation due 2023-10-16
The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7.
8.8
CVSS
29.2%
EPSS (exploit prob.)
98th
EPSS percentile
2023-09-21
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weaknesses
CWE-754
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| apple | ipados | < 17.0.1 |
| apple | iphone_os | < 17.0.1 |
| apple | macos | < 14.0 |
| fedoraproject | fedora | 37 |
| fedoraproject | fedora | 38 |
| fedoraproject | fedora | 39 |
| debian | debian_linux | 11.0 |
| debian | debian_linux | 12.0 |
| oracle | graalvm | 20.3.13 |
| oracle | graalvm | 21.3.9 |
| oracle | jdk | 1.8.0 |
| oracle | jre | 1.8.0 |
| netapp | active_iq_unified_manager | all versions |
| netapp | active_iq_unified_manager | all versions |
| netapp | cloud_insights_acquisition_unit | all versions |
| netapp | cloud_insights_storage_workload_security_agent | all versions |
| netapp | oncommand_insight | all versions |
| netapp | oncommand_workflow_automation | all versions |
| webkitgtk | webkitgtk+ | < 2.42.2 |
Check a specific version with /api/v1/cve/match.
References
- https://security.gentoo.org/glsa/202401-33
- https://security.netapp.com/advisory/ntap-20240426-0004/
- https://support.apple.com/en-us/HT213940
- https://security.gentoo.org/glsa/202401-33
- https://security.netapp.com/advisory/ntap-20240426-0004/
- https://support.apple.com/en-us/HT213940
- https://support.apple.com/kb/HT213926
- https://support.apple.com/kb/HT213930
- https://webkitgtk.org/security/WSA-2023-0009.html
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-41993
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2023-41993