CVE-2023-20745

CVSS 3.1 Score 6.7 of 10 (medium)

Details

Published Jun 6, 2023
Updated: Jan 7, 2025
CWE ID 667

Summary

CVE-2023-20745 is a vulnerability affecting the vcu software. This issue involves an out-of-bounds write caused by insufficient locking, enabling a local privilege escalation. With System execution privileges required, attackers can exploit this vulnerability without user interaction. To address this security concern, the patch ID ALPS07519142 and issue ID ALPS07560694 have been released.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Android

Affected Vendors

  • Google
  • Linux Foundation