VDB
CVE-2023-33864
CVE-2023-33864
PUBLISHED
CVSS 9.300000190734863 CRITICAL
RenderDoc through 1.26 allows an Integer Overflow with a resultant Buffer Overflow (issue 2 of 2).
EPSS 4.16% · 90.6th percentile
Risk Scores
CVSS 4.0
9.300000190734863
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS Score
4.16%
90.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | *, n/a |
| renderdoc | renderdoc | 0, 0 |
Timeline
- Jun 7, 2023 CVE Published
- Jun 8, 2023 PoC Published
- Jun 8, 2023 EPSS Score
- Jun 8, 2023 PoC Published
- Jul 14, 2023 EPSS Score
- Sep 24, 2023 EPSS Score
- Oct 30, 2023 EPSS Score
- Dec 5, 2023 EPSS Score
- Jan 10, 2024 EPSS Score
- Mar 22, 2024 EPSS Score
- Apr 27, 2024 EPSS Score
- Jun 2, 2024 EPSS Score
References
- GLSA-202311-10 advisory
- https://renderdoc.org/ url
- http://packetstormsecurity.com/files/172804/RenderDoc-1.26-Local-Privilege-Escalation-Remote-Code-Execution.html exploit
- https://lists.debian.org/debian-lts-announce/2023/07/msg00023.html advisory
- https://lists.debian.org/debian-lts-announce/2024/12/msg00008.html advisory
- https://www.qualys.com/2023/06/06/renderdoc/renderdoc.txt exploit
- https://nvd.nist.gov/vuln/detail/CVE-2023-33864 advisory
- https://renderdoc.org url
- http://seclists.org/fulldisclosure/2023/Jun/2 url