CVE-2023-0266
Es existieren mehrere Schwachstellen in Samsung Android und mehreren Google-Komponenten. Die Fehler bestehen unter anderem aufgrund einer unsachgemäßen Privilegienverwaltung, einem Heap-Out-of-Bound-Write und einer unsachgemäßen Knox-ID-Validierung. Ein entfernter, anonymer, lokaler oder physischer Angreifer kann diese Schwachstellen ausnutzen, um beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, seine Privilegien zu erweitern und einen Denial-of-Service-Zustand auszulösen. Die erfolgreiche Ausnutzung der Schwachstellen erfordert eine Benutzerinteraktion.
EPSS 0.18% · 39.2th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Oracle | Oracle Linux | |
| IBM | IBM Spectrum Protect plus 10.1 | |
| Amazon | Amazon Linux 2 | |
| Samsung | Samsung Android 13 | |
| Juniper | Juniper EX Series EX9200 | |
| Juniper | Juniper SRX Series | |
| NetApp | NetApp FAS | |
| Red Hat | Red Hat Enterprise Linux | |
| Samsung | Samsung Android 12 | |
| Juniper | Juniper JUNOS ACX7024 | |
| Juniper | Juniper JUNOS Evolved | |
| NetApp | NetApp AFF | |
| Juniper | Juniper JUNOS | |
| Google Android 13 | ||
| Juniper | Juniper JUNOS PTX Series | |
| Ubuntu | Ubuntu Linux | |
| Google Android Pixel | ||
| SUSE | SUSE Linux | |
| Samsung | Samsung Android 11 | |
| Juniper | Juniper EX Series 4400 |
…and 15 more
Exploit Intelligence
- Demo showing Claude Opus does not find CVE-2023-0266 (github-poc-repo)
- Demo showing Claude Opus does not find CVE-2023-0266 (github-poc-repo)
- Demo showing Claude Opus does not find CVE-2023-0266 (github-poc-repo)
- Demo showing Claude Opus does not find CVE-2023-0266 (github-poc-repo)
- Demo showing Claude Opus does not find CVE-2023-0266 (github-poc-repo)
- Demo showing Claude Opus does not find CVE-2023-0266 (github-poc-repo)
- Demo showing Claude Opus does not find CVE-2023-0266 (github-poc-repo)
- Demo showing Claude Opus does not find CVE-2023-0266 (github-poc)
- Demo showing Claude Opus does not find CVE-2023-0266 (github-poc)
- Demo showing Claude Opus does not find CVE-2023-0266 (github-poc)
…and 39 more exploits
Timeline
- May 26, 2017 PoC Published
- Nov 4, 2021 PoC Published
- Jan 17, 2023 CVE Published
- Jan 31, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Mar 12, 2023 EPSS Score
- Mar 30, 2023 CISA KEV Added
- Apr 21, 2023 EPSS Score
- May 1, 2023 PoC Published
- Jun 1, 2023 EPSS Score
- Aug 20, 2023 EPSS Score
- Sep 29, 2023 EPSS Score
References
- https://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-0112.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2023-0112 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-47929 advisory
- https://lists.debian.org/debian-security-announce/2023/msg00013.html advisory
- https://lists.suse.com/pipermail/sle-security-updates/2023-January/013530.html advisory
- https://alas.aws.amazon.com/AL2/ALASKERNEL-5.15-2023-013.html advisory
- https://alas.aws.amazon.com/AL2/ALAS-2023-1932.html advisory
- https://alas.aws.amazon.com/AL2/ALASKERNEL-5.10-2023-026.html advisory
- https://lists.suse.com/pipermail/sle-security-updates/2023-February/013743.html advisory
- https://lists.suse.com/pipermail/sle-security-updates/2023-February/013758.html advisory
- https://lists.suse.com/pipermail/sle-security-updates/2023-February/013764.html advisory
- https://lists.suse.com/pipermail/sle-security-updates/2023-February/013757.html advisory
- https://lists.suse.com/pipermail/sle-security-updates/2023-February/013767.html advisory
- https://lists.suse.com/pipermail/sle-security-updates/2023-February/013801.html advisory
- https://lists.suse.com/pipermail/sle-security-updates/2023-February/013878.html advisory
- https://alas.aws.amazon.com/AL2/ALASKERNEL-5.4-2023-042.html advisory
- https://ubuntu.com/security/notices/USN-5915-1 advisory
- https://lists.debian.org/debian-lts-announce/2023/03/msg00000.html advisory
- https://security.netapp.com/advisory/ntap-20230302-0005/ advisory
- https://ubuntu.com/security/notices/USN-5917-1 advisory
…and 125 more