By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Confluence News - Breaking News, Latest News and VideosConfluence News - Breaking News, Latest News and Videos
Notification Show More
Latest News
Chromebook Plus buyers will get a free trial of the new web-based Photoshop
Tech
Seahawks beat Giants on MNF, defense steals the show
Sports
New post-Brexit border controls to cost businesses £330m a year | Politics News
Business
Trans women to be banned from female hospital wards, under new Tory proposals | Politics News
U.K News
Gmail will finally get a time-saving emoji feature, but there’s a catch
Tech
Aa
  • Home
  • Politics
  • Business
  • LifeStyle
  • Sports
  • Entertainment
  • Health
  • Tech
Reading: Apple iTunes has a serious security flaw you really should know about
Share
Aa
Confluence News - Breaking News, Latest News and VideosConfluence News - Breaking News, Latest News and Videos
  • ES Money
  • U.K News
  • Entertainment
  • Science
  • Technology
  • Insider
Search
  • Home
  • Politics
  • Business
  • Sports
  • Entertainment
  • Health
  • Life Style
  • Tech
Have an existing account? Sign In
Follow US
Confluence News - Breaking News, Latest News and Videos > Blog > Tech > Apple iTunes has a serious security flaw you really should know about
Tech

Apple iTunes has a serious security flaw you really should know about

Last updated: 2023/06/02 at 7:47 PM
Tech Radar Pro
Share
SHARE

A high-severity vulnerability has been discovered in Apple’s iconic iTunes program that could allow threat actors to escalate privileges locally, essentially giving them the keys to the kingdom. 

Cybersecurity researchers from Synopsys outlined the flaw in the Windows version of the multimedia hub, explaining that the app creates a privileged folder with weak access controls.

As a result, a threat actor (in this case, a regular user without any elevated privileges) can redirect this folder creation to the Windows system directory, and then use the folder to obtain a higher-privileged system shell. 

High severity iTunes flaw

“The iTunes application creates a folder, SC Info, in the C:ProgramDataApple ComputeriTunes directory as a system user and gives full control over this directory to all users,” the researchers explained. “After the installation, the first user to run the iTunes application can delete the SC Info folder, create a link to the Windows system folder, and re-create the folder by forcing an MSI repair, which can be later used to gain Windows SYSTEM level access.”

The flaw is now tracked as CVE-2023-32353, affecting iTunes versions prior to 12.12.9. It has a severity score of 7.8 and is deemed “high severity”.

Apple has been hard at work lately remedying a number of high-severity vulnerabilities across its ecosystem. 

Microsoft recently reported finding  a major bug in macOS, dubbed Migraine which could have allowed threat actors with root privileges to bypass System Integrity Protection, giving them the ability to install “undeletable” malware. 

Furthermore, the flaw allows threat actors to work around Transparency, Consent, and Control (TCC) feature, and access sensitive data. The bug has since been patched across the Apple ecosystem, with users told to apply the fix as soon as they can.

Also, less than a month ago, the company announced fixing two zero-day vulnerabilities that were apparently being abused in the wild to target iPhone, Mac, and iPad endpoint users. The flaws enabled threat actors to take full control over the vulnerable devices, it was said.



Source link

You Might Also Like

Chromebook Plus buyers will get a free trial of the new web-based Photoshop

Gmail will finally get a time-saving emoji feature, but there’s a catch

Quordle today – hints and answers for Tuesday, October 3 (game #617)

Apple secretly working on Google Search killer for ‘years,’ probably won’t ever launch

Tech Radar Pro June 2, 2023
Share this Article
Facebook Twitter Email Print
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Follow US

Find US on Social Medias
Facebook Like
Twitter Follow
Youtube Subscribe
Telegram Follow

Weekly Newsletter

Subscribe to our newsletter to get our newest articles instantly!

[mc4wp_form]
Popular News
U.K News

Netflix begins crackdown on households sharing passwords | Science & Tech News

Sky News RSS Sky News RSS May 23, 2023
2023 Grammys: Best looks of the night CNN.com – RSS Channel – HP Hero
Sources: Stafford uncertain to return this season www.espn.com – TOP
Is Germany’s trade too dependent on China?
Despite Biden’s warnings, US has seen no change in Russia’s nuclear posture CNN.com – RSS Channel – HP Hero
- Advertisement -
Ad imageAd image
Global Coronavirus Cases

Confirmed

0

Death

0

More Information:Covid-19 Statistics

Categories

  • ES Money
  • Insider
  • Science
  • Technology
  • LifeStyle

About US

We influence 20 million users and is the number one business and technology news network on the planet.
Quick Link
  • Economy
  • Politics
  • Life Style
  • Contact Us
Top Categories
  • Business
  • Tech
  • Top
  • Health
  • Entertainment

Subscribe US

Subscribe to our newsletter to get our newest articles instantly!

© confluencenews. All Rights Reserved.

Removed from reading list

Undo
Welcome Back!

Sign in to your account

Lost your password?