Impact
Mounting a maliciously crafted AFP network share can cause the system to terminate, effectively denying service to legitimate users. The weakness is classified as CWE‑404, indicating improper resource shutdown or release, which allows the attacker to induce a crash by manipulating the file‑system protocol handling. The impact is local to the affected machine but can disrupt multiple users if the device hosts critical services.
Affected Systems
Apple macOS platforms are affected. The issue is fixed in macOS Sequoia 15.5, macOS Sonoma 14.7.6, and macOS Ventura 13.7.6. Prior versions lacking these updates remain vulnerable.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity vulnerability. However, the EPSS score of less than 1% suggests exploitation is unlikely in the near term, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a network attacker mounting a malicious AFP share; the attacker would need network access to the target and the ability to craft a problematic share. Overall risk is high for exposed devices but low probability of current exploitation.
OpenCVE Enrichment
EUVD