KEVIntel
4.4
CVSS
Medium

CVE-2023-21492

PUBLISHED

Kernel pointers are printed in the log file prior to SMR May-2023 Release 1 allows a privileged local attacker to bypass ASLR.

Exploited in the wild Low complexity No user interaction
Vendor
Samsung Mobile
Product
Samsung Mobile Devices
Published
May 04, 2023
EPSS

Description

Kernel pointers are printed in the log file prior to SMR May-2023 Release 1 allows a privileged local attacker to bypass ASLR.

cisa

CVSS scores

CVSS v3.1 4.4 Medium

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

Exploitation status

Exploited in the wild

Recorded 2023-05-19 00:00:00 UTC · Source

SSVC decision points

Exploitation
active
Automatable
No
Technical impact
partial

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CISA May 19, 2023

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel