CVE-2023-42935

An authentication issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.6.4. A local attacker may be able to view the previous logged in user’s desktop from the fast user switching screen.
References
Link Resource
http://seclists.org/fulldisclosure/2024/Jan/37 Mailing List Third Party Advisory
https://support.apple.com/en-us/HT214058 Release Notes Vendor Advisory
https://support.apple.com/kb/HT213984 Release Notes Vendor Advisory
http://seclists.org/fulldisclosure/2024/Jan/37 Mailing List Third Party Advisory
https://support.apple.com/en-us/HT214058 Release Notes Vendor Advisory
https://support.apple.com/kb/HT213984 Release Notes Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

History

21 Nov 2024, 08:23

Type Values Removed Values Added
References () http://seclists.org/fulldisclosure/2024/Jan/37 - Mailing List, Third Party Advisory () http://seclists.org/fulldisclosure/2024/Jan/37 - Mailing List, Third Party Advisory
References () https://support.apple.com/en-us/HT214058 - Release Notes, Vendor Advisory () https://support.apple.com/en-us/HT214058 - Release Notes, Vendor Advisory
References () https://support.apple.com/kb/HT213984 - Release Notes, Vendor Advisory () https://support.apple.com/kb/HT213984 - Release Notes, Vendor Advisory

29 Jan 2024, 18:38

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
First Time Apple
Apple macos
CPE cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
CWE NVD-CWE-noinfo
References () http://seclists.org/fulldisclosure/2024/Jan/37 - () http://seclists.org/fulldisclosure/2024/Jan/37 - Mailing List, Third Party Advisory
References () https://support.apple.com/kb/HT213984 - () https://support.apple.com/kb/HT213984 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/HT214058 - () https://support.apple.com/en-us/HT214058 - Release Notes, Vendor Advisory

26 Jan 2024, 17:15

Type Values Removed Values Added
References
  • () http://seclists.org/fulldisclosure/2024/Jan/37 -

23 Jan 2024, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-23 01:15

Updated : 2024-11-21 08:23


NVD link : CVE-2023-42935

Mitre link : CVE-2023-42935

CVE.ORG link : CVE-2023-42935


JSON object : View

Products Affected

apple

  • macos