Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Apple Critical Update - 20241030001 #1073

Merged
merged 25 commits into from
Oct 30, 2024
Merged
Changes from all commits
Commits
Show all changes
25 commits
Select commit Hold shift + click to select a range
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
26 changes: 26 additions & 0 deletions docs/advisories/20241030001-Apple-Critical-Update.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,26 @@
# Apple Critical Update - 20241030001

## Overview

Apple has released updates for multiple products. The WA SOC has been made aware of some vulnerabilities being classified as critical.

## What is vulnerable?

| Product(s) Affected | Version(s) | CVE | CVSS | Severity |
| ------------------- | -------------------- | ----------------------------------------------------------------- | ---- | ------------ |
| iOS and iPadOS | all versions < 18.1 | [CVE-2024-40867](https://nvd.nist.gov/vuln/detail/CVE-2024-40867) | 9.6 | **Critical** |

## What has been observed?

There is no evidence of exploitation affecting Western Australian Government networks at the time of publishing.

## Recommendation

The WA SOC recommends administrators apply the solutions as per vendor instructions to all affected devices within expected timeframe of *48 hours...* (refer [Patch Management](../guidelines/patch-management.md)):

- Apple October iOS and iPadOS 18.1 Release Notes: <https://support.apple.com/en-us/121563>
- Apple Security Realses Overview: <https://support.apple.com/en-us/100100>

## Additional References

- SecurityOnline article: <https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-apple-products-could-allow-for-arbitrary-code-execution_2024-121>
Loading