EXPOSURES › CVE-2023-4911
CVE-2023-4911
HIGH ⌖ ON CISA KEV · EXPLOITEDLocal attacker can execute code with elevated privileges due to buffer overflow in GNU C Library.
A buffer overflow vulnerability in GNU C Library's dynamic loader allows a local attacker to execute code with elevated privileges. This is a high-severity issue that could lead to privilege escalation and should be patched immediately.
Shame score — The vulnerability is actively exploited and allows for remote code execution, which is a significant security risk.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
GNU C Library's dynamic loader ld.so contains a buffer overflow vulnerability when processing the GLIBC_TUNABLES environment variable, allowing a local attacker to execute code with elevated privileges.