CVE-2023-33078
CVSS 3.1 Score 5.5 of 10 (medium)
Details
Published Mar 4, 2024
Updated: Jan 10, 2025
CWE ID 125
CWE ID 126
Summary
CVE-2023-33078 is a newly discovered information disclosure vulnerability affecting FastRPC, a remote procedure call (RPC) implementation. The flaw arises during the processing of an Input/Output Control (IOCTL) request, allowing attackers to potentially access sensitive information from the system. Successful exploitation may lead to unintended data exposure, posing a risk to the confidentiality and integrity of affected systems. It is recommended that users apply the available patch or mitigation measures to prevent potential attacks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Qualcomm Incorporated