EXPOSURES › CVE-2023-5217
CVE-2023-5217
HIGH ⌖ ON CISA KEV · EXPLOITEDGoogle Chromium libvpx heap buffer overflow allows remote code execution.
A remote attacker can exploit a heap buffer overflow in Google Chromium libvpx, leading to potential code execution. This vulnerability impacts web browsers using libvpx, including Google Chrome. DIB orgs should ensure their systems are updated to mitigate this risk.
Shame score — The vulnerability was actively exploited and could lead to remote code execution, impacting a widely-used web browser.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Google Chromium libvpx contains a heap buffer overflow vulnerability in vp8 encoding that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could impact web browsers using libvpx, including but not limited to Google Chrome.
| PRODUCT | STATUS |
|---|---|
| Google Services (Google Cloud Platform Products and underlying Infrastructure) Google |
Authorized |
| Google Workspace Google |
Authorized |