CVE-2023-42527

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Nov 7, 2023
Updated: Nov 13, 2023
CWE ID 20

Summary

CVE-2023-42527 is a vulnerability affecting the ProcessWriteFile function in libsec-ril before the SMR Nov-2023 Release 1. An attacker can exploit this improper input validation issue to expose sensitive information on a local system. By providing invalid input to the function, an adversary can potentially bypass security checks, leading to unintended data disclosure. This vulnerability poses a significant risk, particularly in environments where the affected library is in use, and should be addressed promptly by applying the necessary patches or updates.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share