An issue was discovered in certain Apple products. iOS before 11 is affected. The issue involves the "Exchange ActiveSync" component. It allows remote attackers to erase a device in opportunistic circumstances by hijacking a cleartext AutoDiscover V1 session during the setup of an Exchange account.
Weaknesses in this category are related to improper assignment or handling of permissions.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/100892 | third party advisory vdb entry |
http://www.securitytracker.com/id/1039385 | third party advisory vdb entry |
https://support.apple.com/HT208112 | vendor advisory |