Skip to content
COOEY

EXPOSURES › CVE-2023-35674

CVE-2023-35674

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2023-09-13 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2023-35674 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 exploited-in-wildunpatched

An Android Framework vulnerability allows privilege escalation, actively exploited in the wild, impacting DIB organizations using Android-powered devices or systems.

CVE-2023-35674 represents an unspecified privilege escalation vulnerability within the Android Framework, currently being exploited. This poses a significant risk to DIB organizations relying on Android devices or embedded systems, potentially compromising system integrity and data confidentiality; immediate patching and mitigation efforts are crucial.

Shame score — The active exploitation of a privilege escalation vulnerability in a core framework component demonstrates a significant security oversight with potentially widespread impact.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Android Framework contains an unspecified vulnerability that allows for privilege escalation.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.