CVE-2017-13905

A race condition was addressed with additional validation. This issue is fixed in tvOS 11.2, iOS 11.2, macOS High Sierra 10.13.2, Security Update 2017-002 Sierra, and Security Update 2017-005 El Capitan, watchOS 4.2. An application may be able to gain elevated privileges.
Race Condition
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.1 HIGH
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
appleCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 68%
VendorProductVersion
appleiphone_os
𝑥
< 11.2
applemac_os_x
10.11 ≤
𝑥
< 10.11.6
applemac_os_x
10.12 ≤
𝑥
< 10.12.6
applemac_os_x
10.11.6
applemac_os_x
10.11.6:security_update_2016-001
applemac_os_x
10.11.6:security_update_2016-002
applemac_os_x
10.11.6:security_update_2016-003
applemac_os_x
10.11.6:security_update_2017-001
applemac_os_x
10.11.6:security_update_2017-002
applemac_os_x
10.11.6:security_update_2017-003
applemac_os_x
10.11.6:security_update_2017-004
applemac_os_x
10.12.6
applemac_os_x
10.12.6:security_update_2017-001
applemacos
𝑥
< 10.13.2
appletvos
𝑥
< 11.2
applewatchos
𝑥
< 4.2
𝑥
= Vulnerable software versions