CVE-2020-3861: Apple iTunes

High severity, CVSS 7.1. EPSS: 0.4% chance of exploitation in the next 30 days.

The issue was addressed with improved permissions logic. This issue is fixed in iTunes for Windows 12.10.4. A user may gain access to protected parts of the file system.

Affected products

  • Apple iTunes: before 12.10.4 (fixed in 12.10.4)

Published 2020-02-27. Last modified 2026-06-17.