CVE-2023-21217: Integer Overflow
Published Dec 4, 2023
·Updated
In PMRWritePMPageList of TBD, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Software
2 affected components
Google Android
Google Android
Event History
Dec 4, 2023
CVE Published
via Android·12:00 AM
CVE Published
via MITRE·10:40 PM
Data Sourced
via MITRE·10:40 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2023-21217?
CVE-2023-21217 is a vulnerability that allows an attacker to elevate privilege on affected Google Android devices.
2
How severe is CVE-2023-21217?
CVE-2023-21217 has a severity level of high (7) on the Common Vulnerability Scoring System (CVSS).
3
Which software is affected by CVE-2023-21217?
CVE-2023-21217 affects Google Android devices.
4
How can I fix CVE-2023-21217?
To fix CVE-2023-21217, it is recommended to apply the security patch provided by Google for Android devices.
5
Where can I find more information about CVE-2023-21217?
You can find more information about CVE-2023-21217 in the Android Security Bulletin for December 2023.