SB2023080875 - Information disclosure in Microsoft Windows Bluetooth A2DP driver
Published: August 8, 2023 Updated: August 15, 2023
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Integer underflow (CVE-ID: CVE-2023-35387)
The vulnerability allows an attacker to gain access to sensitive information.
The vulnerability exists due to integer underflow when processing AVDTP commands in Windows Bluetooth A2DP driver. An attacker with physical proximity to device can send a specially crafted packets to the system to trigger an integer underflow and gain access to sensitive information.
Remediation
Install update from vendor's website.