CVSS 3.1 Score 5.5 of 10 (medium)


Published Oct 28, 2023
Updated: Nov 21, 2023
CWE ID 125


CVE-2023-45897, also known as CWE-125 (Out-of-bounds Read), is a vulnerability found in exfatprogs before version 1.2.2. This vulnerability allows for out-of-bounds memory access, specifically in the read_file_dentry_set function. It affects multiple products, including tUi2x1, tUi2x2, tUi2x3, tUi2x4, tUi2x5, tUi2x6, tUi2x7, tUi2x8, and tUi2x9. The risk score for this vulnerability is 26, with a base severity of MEDIUM and a base score of 5.5. The exploitability score is 1.8, indicating a low privilege requirement and no user interaction needed. The attack vector is local and the integrity impact is high. To remediate this vulnerability, users should update their exfatprogs to version 1.2.2 or later to prevent potential unauthorized access to sensitive data stored on affected systems.

Explore Beyond the CVE Basics with Recorded Future's Vulnerability Intelligence

Note: This is just a basic overview providing quick insights into CVE-2023-45897 information. Gain full access to comprehensive CVE data, risk scores, prioritization, and mitigation data through Recorded Future's Vulnerability Intelligence:
  • Prioritize with Risk-Based Scoring
  • Explore the Extensive Vulnerability Database
  • Receive Early Alerts on Emerging CVEs
  • Focus on Critical Exploitable Vulnerabilities
  • Streamline Remediation with Integration Options