Skip to content
COOEY

EXPOSURES › CVE-2023-4911

CVE-2023-4911

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2023-11-21 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2023-4911 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 exploited-in-wildunpatched

Local attacker can execute code with elevated privileges due to buffer overflow in GNU C Library.

A buffer overflow vulnerability in GNU C Library's dynamic loader allows a local attacker to execute code with elevated privileges. This is a high-severity issue that could lead to privilege escalation and should be patched immediately.

Shame score — The vulnerability is actively exploited and allows for remote code execution, which is a significant security risk.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

GNU C Library's dynamic loader ld.so contains a buffer overflow vulnerability when processing the GLIBC_TUNABLES environment variable, allowing a local attacker to execute code with elevated privileges.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.