CVE-2023-30666

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Jul 6, 2023
Updated: Nov 7, 2023
CWE ID 787

Summary

CVE-2023-30666 is a vulnerability affecting the DoOemImeiSetPreconfig function in libsec-ril before the SMR Jul-2023 Release 1. This issue stems from improper input validation, enabling local attackers to execute an Out-Of-Bounds write. Successful exploitation could result in unintended code execution or system crashes, potentially leading to significant security risks. System administrators are advised to apply the latest software updates to mitigate this vulnerability and secure their systems against local attackers.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share