CVE-2023-27352: (Pwn2Own) Sonos One Speaker libsmb2 Use-After-Free Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sonos One Speaker 70.3-35220. Authentication is not required to exploit this vulnerability. The specific flaw exists within the processing of the SMB directory query command. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-19845.
Other sources
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sonos One Speaker. Authentication is not required to exploit this vulnerability. The specific flaw exists within the processing of the SMB directory query command. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of root.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-27352?
CVE-2023-27352 is a high-severity vulnerability that allows network-adjacent attackers to execute arbitrary code without authentication.
How do I fix CVE-2023-27352?
To mitigate CVE-2023-27352, update your Sonos One Speaker to the latest firmware version that addresses this vulnerability.
Who is affected by CVE-2023-27352?
CVE-2023-27352 affects installations of Sonos One Speaker firmware version 70.3-35220.
What type of attack can exploit CVE-2023-27352?
CVE-2023-27352 can be exploited by network-adjacent attackers to execute arbitrary code remotely on vulnerable devices.
Is authentication required to exploit CVE-2023-27352?
No, authentication is not required to exploit CVE-2023-27352, making it more critical for affected users.