CVE-2023-32353 is a high-severity logic issue affecting Apple iTunes for Windows, specifically versions prior to 12.12.9. This vulnerability could allow an application to elevate its privileges, potentially leading to unauthorized access or control. With a CVSS score of 7.8, it presents a significant risk due to its low attack complexity and high impact on confidentiality, integrity, and availability. While no public exploit code or active exploitation has been observed, and community discussion is minimal, users are strongly advised to update iTunes to version 12.12.9 or later to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 12.12.9CPE matchmatch criteria | cpe:2.3:a:apple:itunes:*:*:*:*:*:windows:*:* | ||
< 12.12CPE match | cpe:2.3:a:apple:itunes:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.