Skip to content
COOEY

EXPOSURES › CVE-2023-5217

CVE-2023-5217

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2023-10-02 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2023-5217 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 exploited-in-wildunpatched

Google Chromium libvpx heap buffer overflow allows remote code execution.

A remote attacker can exploit a heap buffer overflow in Google Chromium libvpx, leading to potential code execution. This vulnerability impacts web browsers using libvpx, including Google Chrome. DIB orgs should ensure their systems are updated to mitigate this risk.

Shame score — The vulnerability was actively exploited and could lead to remote code execution, impacting a widely-used web browser.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Google Chromium libvpx contains a heap buffer overflow vulnerability in vp8 encoding that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could impact web browsers using libvpx, including but not limited to Google Chrome.

AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
Google Services (Google Cloud Platform Products and underlying Infrastructure)
Google
Authorized
Google Workspace
Google
Authorized