EXPOSURES › CVE-2023-35674
CVE-2023-35674
HIGH ⌖ ON CISA KEV · EXPLOITEDAn Android Framework vulnerability allows privilege escalation, actively exploited in the wild, impacting DIB organizations using Android-powered devices or systems.
CVE-2023-35674 represents an unspecified privilege escalation vulnerability within the Android Framework, currently being exploited. This poses a significant risk to DIB organizations relying on Android devices or embedded systems, potentially compromising system integrity and data confidentiality; immediate patching and mitigation efforts are crucial.
Shame score — The active exploitation of a privilege escalation vulnerability in a core framework component demonstrates a significant security oversight with potentially widespread impact.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Android Framework contains an unspecified vulnerability that allows for privilege escalation.