macOS 10.13.6 Multiple Vulnerabilities (Security Update 2018-002)

critical Nessus Plugin ID 118575

Synopsis

The remote host is missing a macOS security update that fixes multiple vulnerabilities.

Description

The remote host is running macOS 10.13.6 and is missing a security update. It is therefore, affected by multiple vulnerabilities affecting the following components :

- fpserver
- AppleGraphicsControl
- APR
- ATS
- CFNetwork
- CoreAnimation
- CoreCrypto
- CoreFoundation
- CUPS
- Dictionary
- dyld
- EFI
- Foundation
- Grand Central Dispatch
- Heimdal
- Hypervisor
- ICU
- Intel Graphics Driver
- IOGraphics
- IOHIDFamily
- IOKit
- IOUserEthernet
- IPSec
- Kernel
- Login Window
- mDNSOffloadUserClient
- MediaRemote
- Microcode
- NetworkExtension
- Security
- Spotlight
- Symptom Framework
- WiFi

Solution

Install Security Update 2018-002 or later for 10.13.6.

See Also

https://support.apple.com/en-us/HT209193

http://www.nessus.org/u?f0681c90

Plugin Details

Severity: Critical

ID: 118575

File Name: macosx_SecUpd_10_13_6_2018-002.nasl

Version: 1.10

Type: local

Agent: macosx

Published: 10/31/2018

Updated: 6/16/2022

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.7

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2018-4331

CVSS v3

Risk Factor: Critical

Base Score: 10

Temporal Score: 9

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

CVSS Score Source: CVE-2018-4310

Vulnerability Information

CPE: cpe:/o:apple:macos, cpe:/o:apple:mac_os_x

Required KB Items: Host/local_checks_enabled, Host/MacOSX/Version, Host/MacOSX/packages/boms

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 10/30/2018

Vulnerability Publication Date: 10/30/2018

Reference Information

CVE: CVE-2017-12613, CVE-2017-12618, CVE-2018-3639, CVE-2018-3640, CVE-2018-3646, CVE-2018-4126, CVE-2018-4153, CVE-2018-4203, CVE-2018-4295, CVE-2018-4304, CVE-2018-4308, CVE-2018-4310, CVE-2018-4326, CVE-2018-4331, CVE-2018-4340, CVE-2018-4341, CVE-2018-4342, CVE-2018-4346, CVE-2018-4348, CVE-2018-4350, CVE-2018-4354, CVE-2018-4368, CVE-2018-4369, CVE-2018-4371, CVE-2018-4393, CVE-2018-4394, CVE-2018-4395, CVE-2018-4396, CVE-2018-4398, CVE-2018-4399, CVE-2018-4400, CVE-2018-4401, CVE-2018-4402, CVE-2018-4406, CVE-2018-4407, CVE-2018-4408, CVE-2018-4410, CVE-2018-4411, CVE-2018-4412, CVE-2018-4413, CVE-2018-4415, CVE-2018-4417, CVE-2018-4418, CVE-2018-4419, CVE-2018-4420, CVE-2018-4422, CVE-2018-4423, CVE-2018-4425, CVE-2018-4426

APPLE-SA: APPLE-SA-2018-10-30-2

IAVA: 2021-A-0356-S