First published: Tue Dec 05 2023(Updated: )
Improper access control in knoxcustom service prior to SMR Dec-2023 Release 1 allows attacker to send broadcast with system privilege.
Credit: mobile.security@samsung.com
Affected Software | Affected Version | How to fix |
---|---|---|
Samsung Android | >=12.0<14.0 | |
Samsung Android | =14.0 | |
Samsung Android | =14.0-smr-apr-2023-r1 | |
Samsung Android | =14.0-smr-aug-2023-r1 | |
Samsung Android | =14.0-smr-dec-2022-r1 | |
Samsung Android | =14.0-smr-feb-2023-r1 | |
Samsung Android | =14.0-smr-jan-2023-r1 | |
Samsung Android | =14.0-smr-jul-2023-r1 | |
Samsung Android | =14.0-smr-jun-2023-r1 | |
Samsung Android | =14.0-smr-mar-2023-r1 | |
Samsung Android | =14.0-smr-may-2023-r1 | |
Samsung Android | =14.0-smr-nov-2022-r1 | |
Samsung Android | =14.0-smr-nov-2023-r1 | |
Samsung Android | =14.0-smr-oct-2022-r1 | |
Samsung Android | =14.0-smr-oct-2023-r1 | |
Samsung Android | =14.0-smr-sep-2023-r1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2023-42564.
The title of this vulnerability is 'Improper access control in knoxcustom service prior to SMR Dec-2023 Release 1 allows attacker to send broadcast with system privilege.'
The severity of CVE-2023-42564 is medium, with a severity value of 6.6.
The affected software for CVE-2023-42564 is Samsung Android versions 12.0 to 14.0.
To fix CVE-2023-42564, update to SMR Dec-2023 Release 1 or a later version of Samsung Android.