CVE-2023-43488

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Oct 25, 2023
Updated: Nov 6, 2023
CWE ID 862

Summary

CVE-2023-43488 is a newly disclosed vulnerability that enables a low privileged application to manipulate a critical system property, granting unauthorized access to the Android Debug Bridge (ADB) protocol over the network. This exposure can lead to a privileged shell on affected devices, bypassing the need for physical USB access. The vulnerability poses a significant risk, as the ADB interface provides comprehensive control over the device, including file manipulation, installation of applications, and access to sensitive data. This issue can be potentially exploited remotely, making it a serious concern for security teams.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share