CVE-2023-28736: Buffer Overflow
Published Aug 11, 2023
·Updated
Buffer overflow in some Intel(R) SSD Tools software before version mdadm-4.2-rc2 may allow a privileged user to potentially enable escalation of privilege via local access.
Affected Software
5 affected componentsFixes available
Mdadm Project Mdadm<4.2
Mdadm Project Mdadm=4.2-rc1
Microsoft cbl2 mdadm 4.1-10
Microsoft azl3 mdadm 4.1-9
Microsoft azl3 mdadm 4.2-1
Event History
Aug 11, 2023
CVE Published
via MITRE·02:36 AM
Data Sourced
via MITRE·02:36 AM
DescriptionSeverityWeakness
Jun 30, 2024
Data Sourced
via Microsoft·02:00 PM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·02:00 PM
Affected Software
Updated
via Microsoft·02:00 PM
DescriptionSeverity
Frequently Asked Questions
1
What is the vulnerability ID for this buffer overflow in Intel SSD Tools software?
The vulnerability ID is CVE-2023-28736.
2
What is the severity rating of CVE-2023-28736?
CVE-2023-28736 has a severity rating of 6.7, which is considered medium.
3
How does the buffer overflow vulnerability in Intel SSD Tools software potentially enable privilege escalation?
The buffer overflow in Intel SSD Tools software may allow a privileged user to potentially enable escalation of privilege through local access.
4
Which software versions are affected by CVE-2023-28736?
The affected software versions are mdadm before version 4.2-rc2 and mdadm version 4.2-rc1.
5
Is there a reference link for more information about this vulnerability?
Yes, you can find more information about CVE-2023-28736 at the following link: http://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00690.html