CVE-2023-20745
CVSS 3.1 Score 6.7 of 10 (medium)
Details
Published Jun 6, 2023
Updated: Jan 7, 2025
CWE ID 667
Summary
CVE-2023-20745 is a vulnerability affecting the vcu software. This issue involves an out-of-bounds write caused by insufficient locking, enabling a local privilege escalation. With System execution privileges required, attackers can exploit this vulnerability without user interaction. To address this security concern, the patch ID ALPS07519142 and issue ID ALPS07560694 have been released.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Android
Affected Vendors
- Linux Foundation