CVE-2023-32891: Input Validation
In bluetooth service, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07933038; Issue ID: MSV-559.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-32891?
CVE-2023-32891 is classified as a critical vulnerability due to its ability to lead to local escalation of privilege.
How do I fix CVE-2023-32891?
To fix CVE-2023-32891, apply the patch identified as ALPS07933038 provided by the respective vendors.
Which systems are affected by CVE-2023-32891?
CVE-2023-32891 affects various Android versions including 11.0, 12.0, and 13.0, along with certain MediaTek devices.
Can CVE-2023-32891 be exploited without user interaction?
Yes, CVE-2023-32891 can be exploited without user interaction, making it particularly severe.
What kind of vulnerability is CVE-2023-32891?
CVE-2023-32891 is an out-of-bounds write vulnerability caused by improper input validation in the Bluetooth service.