CVE-2023-27355: (Pwn2Own) Sonos One Speaker MPEG-TS Parser Stack-based Buffer Overflow Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sonos One Speaker 70.3-35220. Authentication is not required to exploit this vulnerability. The specific flaw exists within the MPEG-TS parser. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-19773.
Other sources
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sonos One Speaker. Authentication is not required to exploit this vulnerability. The specific flaw exists within the MPEG-TS parser. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-27355?
CVE-2023-27355 has a critical severity level due to the potential for arbitrary code execution.
How do I fix CVE-2023-27355?
To mitigate CVE-2023-27355, ensure your Sonos One Speaker is updated to the latest firmware version that addresses this vulnerability.
Who is affected by CVE-2023-27355?
CVE-2023-27355 affects installations of the Sonos One Speaker running firmware version 70.3-35220.
Are authentication measures needed to exploit CVE-2023-27355?
No, CVE-2023-27355 can be exploited without any authentication.
What type of vulnerability is CVE-2023-27355?
CVE-2023-27355 is a code execution vulnerability that exists within the MPEG-TS parser.