Integer underflow in Microsoft Windows and Windows Server - CVE-2023-35387

 

Integer underflow in Microsoft Windows and Windows Server - CVE-2023-35387

Published: August 8, 2023 / Updated: August 15, 2023


Vulnerability identifier: #VU79169
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-35387
CWE-ID: CWE-191
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows an attacker to gain access to sensitive information.

The vulnerability exists due to integer underflow when processing AVDTP commands in Windows Bluetooth A2DP driver. An attacker with physical proximity to device can send a specially crafted packets to the system to trigger an integer underflow and gain access to sensitive information.


Affected software

Microsoft Windows
Windows Server

How to mitigate CVE-2023-35387

Install updates from vendor's website.


External References

Related Security Bulletins