CVE-2023-21062
Published on: Not Yet Published
Last Modified on: 03/31/2023 12:58:00 PM UTC
Certain versions of Android from Google contain the following vulnerability:
In DoSetTempEcc of imsservice.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-243376770References: N/A
- CVE-2023-21062 has been assigned by
secur[email protected] to track the vulnerability - currently rated as MEDIUM severity.
CVSS3 Score: 6.7 - MEDIUM
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
LOCAL | LOW | HIGH | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Pixel Update Bulletin—March 2023 | Android Open Source Project | source.android.com text/html |
![]() |
Related QID Numbers
- 610470 Google Pixel Android March 2023 Security Patch Missing
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Operating System | Android | - | All | All | All |
- cpe:2.3:o:google:android:-:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2023-21062 : In #DoSetTempEcc of imsservice.cpp, there is a possible out of bounds read due to an incorrect bou… twitter.com/i/web/status/1… | 2023-03-24 20:47:29 |