Integer underflow in Microsoft Windows and Windows Server - CVE-2023-35387
Published: August 8, 2023 / Updated: August 15, 2023
Vulnerability details
The vulnerability allows an attacker to gain access to sensitive information.
The vulnerability exists due to integer underflow when processing AVDTP commands in Windows Bluetooth A2DP driver. An attacker with physical proximity to device can send a specially crafted packets to the system to trigger an integer underflow and gain access to sensitive information.
Affected software
Windows Server