CVE-2023-21144
Last modified
CVE-2023-21144 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. In doInBackground of NotificationContentInflater.java, there is a possible temporary denial or service due to long running operations. This could lead to remote denial of service with no additional execution privileges needed. EPSS estimates a 0.74% chance of exploitation in the next 30 days.
Description
In doInBackground of NotificationContentInflater.java, there is a possible temporary denial or service due to long running operations. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-252766417
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Android | 11.0 | |
| Android | 12.0 | |
| Android | 12.1 | |
| Android | 13.0 |
References
- https://source.android.com/security/bulletin/2023-06-01Patch, Vendor Advisory
- https://source.android.com/security/bulletin/2023-06-01Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-21144?
How severe is CVE-2023-21144?
How do I fix CVE-2023-21144?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-21139In bindPlayer of MediaControlPanel.java, there is a possible…7.8
- CVE-2023-2114The NEX-Forms WordPress plugin before 8.4 does not properly …7.2
- CVE-2023-21140In onCreate of ManagePermissionsActivity.java, there is a po…6.8
- CVE-2023-21141In several functions of several files, there is a possible w…5.5
- CVE-2023-21142In multiple files, there is a possible way to access traces …5.5
- CVE-2023-21143In multiple functions of multiple files, there is a possible…5.5
- CVE-2023-21145In updatePictureInPictureMode of ActivityRecord.java, there …7.8
- CVE-2023-21146there is a possible way to corrupt memory due to a use after…6.7
- CVE-2023-21147In lwis_i2c_device_disable of lwis_device_i2c.c, there is a …7.8
- CVE-2023-21148In BuildSetConfig of protocolimsbuilder.cpp, there is a poss…4.4
- CVE-2023-21149In registerGsmaServiceIntentReceiver of ShannonRcsService.ja…7.8
- CVE-2023-21150In handle_set_parameters_ctrl of hal_socket.c, there is a po…4.4
Are you affected by CVE-2023-21144?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
