Skip to content
COOEY

EXPOSURES › CVE-2023-33107

CVE-2023-33107

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2023-12-05 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2023-33107 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 65/100 exploited-in-wildunpatchedransomware

Qualcomm chipsets contain an integer overflow vulnerability in Graphics Linux that allows memory corruption during IOCTL calls.

This integer overflow vulnerability in Qualcomm chipsets enables memory corruption during shared virtual memory region assignment via IOCTL calls, posing a significant risk to DIB organizations relying on Qualcomm hardware for secure systems. The vulnerability is actively exploited in the KEV list, indicating widespread real-world impact and requiring immediate vendor patching and system isolation to prevent potential remote code execution.

Shame score — Active exploitation in KEV list indicates widespread impact and requires immediate remediation to prevent potential remote code execution.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Multiple Qualcomm chipsets contain an integer overflow vulnerability due to memory corruption in Graphics Linux while assigning shared virtual memory region during IOCTL call.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.