{"id":6343,"date":"2019-10-16T09:16:39","date_gmt":"2019-10-16T13:16:39","guid":{"rendered":"http:\/\/community.mis.temple.edu\/mis5211sec001fall2019\/?p=6343"},"modified":"2019-10-16T09:16:39","modified_gmt":"2019-10-16T13:16:39","slug":"vulnerability-in-itunes-and-icloud-for-windows","status":"publish","type":"post","link":"https:\/\/community.mis.temple.edu\/mis5211sec001fall2019\/2019\/10\/16\/vulnerability-in-itunes-and-icloud-for-windows\/","title":{"rendered":"Vulnerability in iTunes and iCloud for Windows"},"content":{"rendered":"<p>A zero-day vulnerability in iTunes and iCloud application was discovered by the security company Morphisec <a href=\"https:\/\/blog.morphisec.com\/apple-zero-day-exploited-in-bitpaymer-campaign\">here <\/a>on October 10th, 2019. The article continues to disclose additional technical details on the vulnerability. The vulnerability in the applications will not trigger an antivirus software detection as the software is signed by Apple, and is automatically flagged as okay. The root cause according to the article is known as an unquoted service path, when a developer forgets to surround a file path with quotation marks. \u00a0&#8220;When the bug is in a trusted program \u2014 such as one digitally signed by a well-known developer like Apple \u2014 attackers can exploit the flaw to make the program execute code that AV protection might otherwise flag as suspicious.&#8221;<\/p>\n<p>As of today, Apple has released the patches for <a href=\"https:\/\/support.apple.com\/en-us\/HT210635\">iTunes<\/a> and <a href=\"https:\/\/support.apple.com\/en-us\/HT210637\">iCloud <\/a>for windows to close the security vulnerability.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A zero-day vulnerability in iTunes and iCloud application was discovered by the security company Morphisec here on October 10th, 2019. The article continues to disclose additional technical details on the vulnerability. The vulnerability in the applications will not trigger an antivirus software detection as the software is signed by Apple, and is automatically flagged as [&hellip;]<\/p>\n","protected":false},"author":23283,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_genesis_hide_title":false,"_genesis_hide_breadcrumbs":false,"_genesis_hide_singular_image":false,"_genesis_hide_footer_widgets":false,"_genesis_custom_body_class":"","_genesis_custom_post_class":"","_genesis_layout":"","footnotes":""},"categories":[803560],"tags":[],"class_list":{"0":"post-6343","1":"post","2":"type-post","3":"status-publish","4":"format-standard","6":"category-week-07-netcat-and-hellcat","7":"entry"},"jetpack_featured_media_url":"","_links":{"self":[{"href":"https:\/\/community.mis.temple.edu\/mis5211sec001fall2019\/wp-json\/wp\/v2\/posts\/6343","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/community.mis.temple.edu\/mis5211sec001fall2019\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/community.mis.temple.edu\/mis5211sec001fall2019\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/community.mis.temple.edu\/mis5211sec001fall2019\/wp-json\/wp\/v2\/users\/23283"}],"replies":[{"embeddable":true,"href":"https:\/\/community.mis.temple.edu\/mis5211sec001fall2019\/wp-json\/wp\/v2\/comments?post=6343"}],"version-history":[{"count":1,"href":"https:\/\/community.mis.temple.edu\/mis5211sec001fall2019\/wp-json\/wp\/v2\/posts\/6343\/revisions"}],"predecessor-version":[{"id":6344,"href":"https:\/\/community.mis.temple.edu\/mis5211sec001fall2019\/wp-json\/wp\/v2\/posts\/6343\/revisions\/6344"}],"wp:attachment":[{"href":"https:\/\/community.mis.temple.edu\/mis5211sec001fall2019\/wp-json\/wp\/v2\/media?parent=6343"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/community.mis.temple.edu\/mis5211sec001fall2019\/wp-json\/wp\/v2\/categories?post=6343"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/community.mis.temple.edu\/mis5211sec001fall2019\/wp-json\/wp\/v2\/tags?post=6343"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}