
====================================================================

                             CERT-Renater

                 Note d'Information No. 2021/VULN244
_____________________________________________________________________

DATE                : 28/04/2021

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S): Windows running iCloud versions prior to 12.3.

=====================================================================
https://support.apple.com/HT212321
_____________________________________________________________________


APPLE-SA-2021-04-26-8 iCloud for Windows 12.3

iCloud for Windows 12.3 addresses the following issues.
Information about the security content is also available at
https://support.apple.com/HT212321.

CFNetwork
Available for: Windows 10 and later via the Microsoft Store
Impact: Processing maliciously crafted web content may disclose
sensitive user information
Description: A memory initialization issue was addressed with
improved memory handling.
CVE-2021-1857: an anonymous researcher

CoreText
Available for: Windows 10 and later via the Microsoft Store
Impact: Processing a maliciously crafted font may result in the
disclosure of process memory
Description: A logic issue was addressed with improved state
management.
CVE-2021-1811: Xingwei Lin of Ant Security Light-Year Lab

WebKit
Available for: Windows 10 and later via the Microsoft Store
Impact: Processing maliciously crafted web content may lead to a
cross site scripting attack
Description: An input validation issue was addressed with improved
input validation.
CVE-2021-1825: Alex Camboe of Aon?s Cyber Solutions

WebRTC
Available for: Windows 10 and later via the Microsoft Store
Impact: A remote attacker may be able to cause unexpected system
termination or corrupt kernel memory
Description: A use after free issue was addressed with improved
memory management.
CVE-2020-7463: Megan2013678

Additional recognition

CoreCrypto
We would like to acknowledge Andy Russon of Orange Group for their
assistance.

Installation note:

This update may be obtained from:
https://support.apple.com/en-us/HT201391

Information will also be posted to the Apple Security Updates
web site: https://support.apple.com/kb/HT201222

This message is signed with Apple's Product Security PGP key,
and details are available at:
https://www.apple.com/support/security/pgp/


=========================================================
+ CERT-RENATER       |    tel : 01-53-94-20-44          +
+ 23/25 Rue Daviel   |    fax : 01-53-94-20-41          +
+ 75013 Paris        |    email:cert@support.renater.fr +
=========================================================




