CVE-2023-20841

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Sep 4, 2023
Updated: Sep 7, 2023
CWE ID 787

Summary

CVE-2023-20841 is a vulnerability affecting the imgsys component. It involves a missing range check, resulting in a potential out-of-bounds write. This issue could be exploited to gain local privilege escalation, requiring System execution privileges. User interaction is necessary for successful exploitation. The patch ID for addressing this issue is ALPS07326455, and it was assigned the internal issue ID ALPS07326441.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Android
  • Linux Kernel

Affected Vendors

  • Google
  • LINUX
  • Linux Foundation
  • Mediatek Inc.