CVE-2023-29166 is a logic issue in Apple Pro Video Formats that, if exploited, could allow a local attacker to elevate privileges. This vulnerability has a high CVSS score of 8.8, indicating a significant risk with low attack complexity and high impact on confidentiality, integrity, and availability. While no public exploits, Metasploit modules, or Nuclei templates are currently available, and there's no evidence of active exploitation or community discussion, the potential for privilege escalation warrants prompt patching. The issue is resolved in Pro Video Formats 2.2.5.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.2.5CPE matchmatch criteria | cpe:2.3:a:apple:pro_video_formats:*:*:*:*:*:*:*:* | ||
< 2.2CPE match | cpe:2.3:a:apple:pro_video_formats:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.