CVE-2022-48611 is a logic issue affecting Apple iTunes for Windows that could allow a local attacker to elevate their privileges. This vulnerability carries a high CVSS score of 7.8 due to its low attack complexity and significant potential for high impact on confidentiality, integrity, and availability. While the vulnerability is patched in iTunes 12.12.4 for Windows, there is no public exploit code, Metasploit modules, or evidence of active exploitation, and it has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 12.12.4CPE matchmatch criteria | cpe:2.3:a:apple:itunes:*:*:*:*:*:windows:*:* | ||
< 12.12.4CPE match | cpe:2.3:a:apple:itunes:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.