Junglewise Threat Intelligence

CVE-2014-4404: Apple OS X Heap-Based Buffer Overflow Vulnerability

CVE-2014-4404 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2022-02-10

Vendors: Apple.

Executive brief

A heap-based buffer overflow vulnerability exists in the IOHIDFamily component of Apple OS X, iOS, and Apple TV. The flaw allows local attackers to execute arbitrary code in a privileged context via an application that provides crafted key-mapping properties.

Affected products

  • Apple iOS before 8
  • Apple Apple TV before 7
  • Apple OS X / macOS before 10.10.0; 10.10.1 to before 10.10.3

Timeline

  • 2014-09-17: disclosed: Initial vendor advisory/bugtraq posting
  • 2022-02-10: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-02-10: exploited: Confirmed as exploited in the wild per CISA KEV entry

Related threats