CVE-2023-42935

An authentication issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.6.4. A local attacker may be able to view the previous logged in user’s desktop from the fast user switching screen.
References
Link Resource
http://seclists.org/fulldisclosure/2024/Jan/37 Mailing List Third Party Advisory
https://support.apple.com/en-us/HT214058 Release Notes Vendor Advisory
https://support.apple.com/kb/HT213984 Release Notes Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

History

29 Jan 2024, 18:38

Type Values Removed Values Added
CWE NVD-CWE-noinfo
CPE cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
First Time Apple
Apple macos
References () http://seclists.org/fulldisclosure/2024/Jan/37 - () http://seclists.org/fulldisclosure/2024/Jan/37 - Mailing List, Third Party Advisory
References () https://support.apple.com/en-us/HT214058 - () https://support.apple.com/en-us/HT214058 - Release Notes, Vendor Advisory
References () https://support.apple.com/kb/HT213984 - () https://support.apple.com/kb/HT213984 - Release Notes, Vendor Advisory

26 Jan 2024, 17:15

Type Values Removed Values Added
References
  • () http://seclists.org/fulldisclosure/2024/Jan/37 -

23 Jan 2024, 13:44

Type Values Removed Values Added
Summary
  • (es) Se solucionó un problema de autenticación con una gestión de estado mejorada. Este problema se solucionó en macOS Ventura 13.6.4. Un atacante local puede ver el escritorio del usuario que inició sesión anteriormente desde la pantalla de cambio rápido de usuario.

23 Jan 2024, 03:15

Type Values Removed Values Added
References
  • () https://support.apple.com/kb/HT213984 -

23 Jan 2024, 01:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-23 01:15

Updated : 2024-01-29 18:38


NVD link : CVE-2023-42935

Mitre link : CVE-2023-42935

CVE.ORG link : CVE-2023-42935


JSON object : View

Products Affected

apple

  • macos