PT-2023-7500 · Microsoft · Azure Rtos Usbx

CVE-2023-48698

·

Publicado

2023-11-17

·

Atualizado

2025-10-27

CVSS v3.1

6.8

Média

VetorAV:P/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Azure RTOS USBX versions prior to 6.3.0
Description The issue is related to expired pointer dereference vulnerabilities in Azure RTOS USBX, which can lead to remote code execution. The affected components include functions and processes in the host stack and host classes, related to device linked classes, GSER, and HID. An attacker can exploit this issue due to insufficient checking of exceptional states resulting from dereferencing an expired pointer.
Recommendations For Azure RTOS USBX versions prior to 6.3.0, upgrade to release 6.3.0 to resolve the issue. As a temporary workaround, consider restricting access to the GSER and HID interfaces in the USB host until the update is applied. Avoid using the affected functions and processes in the host stack and host classes related to device linked classes until the issue is resolved.

Exploit

Correção

RCE

Improper Check for Exceptional Conditions

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-08545
CVE-2023-48698
GHSA-GRHP-F66Q-X857

Produtos afetados

Azure Rtos Usbx