CVE-2024-23717: Buffer Overflow
In accesssecureservicefromtempbond of btmsec.cc, there is a possible way to achieve keystroke injection due to improper input validation. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Software
Remediation
Patch Available
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-23717?
CVE-2024-23717 is classified as a high severity vulnerability due to the potential for privilege escalation.
How do I fix CVE-2024-23717?
To mitigate CVE-2024-23717, update your Android device to the latest available version that includes the security patches.
Which versions of Android are affected by CVE-2024-23717?
CVE-2024-23717 affects Google Android versions 12.0, 12.1, 13.0, and 14.0.
What type of attack does CVE-2024-23717 enable?
CVE-2024-23717 enables keystroke injection attacks that could lead to local privilege escalation.
Is user interaction required to exploit CVE-2024-23717?
No, exploiting CVE-2024-23717 does not require user interaction.