CVE-2023-52890: Use After Free
Published Jun 13, 2024
·Updated
NTFS-3G before 75dcdc2 has a use-after-free in ntfsuppercasembs in libntfs-3g/unistr.c. NOTE: discussion suggests that exploitation would be challenging.
Affected Software
3 affected componentsFixes available
tuxera NTFS-3G<75dcdc2
Microsoft azl3 ntfs-3g 2022.10.3-2
Microsoft cbl2 ntfs-3g 2022.10.3-2
Event History
Jun 13, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 AM
DescriptionSeverity
Jun 30, 2024
Data Sourced
via Microsoft·02:00 PM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·02:00 PM
Affected Software
Updated
via Microsoft·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-52890?
CVE-2023-52890 has a moderate severity due to the potential for a use-after-free vulnerability.
2
How do I fix CVE-2023-52890?
To mitigate CVE-2023-52890, upgrade to a version of Tuxera NTFS-3G greater than 75dcdc2.
3
What causes CVE-2023-52890?
CVE-2023-52890 is caused by a use-after-free condition in the ntfs_uppercase_mbs function within NTFS-3G.
4
Is exploitation of CVE-2023-52890 easy?
Exploitation of CVE-2023-52890 is considered challenging, according to discussions in the CVE report.
5
Which versions of NTFS-3G are affected by CVE-2023-52890?
All versions of Tuxera NTFS-3G prior to version 75dcdc2 are affected by CVE-2023-52890.