CVE-2017-13811 is a memory corruption vulnerability in the fsck_msdos component of macOS versions prior to 10.13.1. This flaw allows an attacker to execute arbitrary code with elevated privileges or trigger a denial of service via a specially crafted application. Rated 7.8 HIGH, it requires user interaction (UI:R) and local access (AV:L), but has high impacts on confidentiality, integrity, and availability. While no public exploit code or active exploitation has been observed, the vulnerability has garnered significant media coverage and community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 10.13.0CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.