Lucene search

K
hiveproHiveForce LabsHIVEPRO:9B939501589F501F39B8A0B608D3AE78
HistoryOct 02, 2023 - 6:29 a.m.

Google and Firefox fixes Zero-Day Flaw Exploited in the Wild

2023-10-0206:29:28
HiveForce Labs
www.hivepro.com
40
zero-day
flaw
cve-2023-5217
google
firefox
patch
heap buffer overflow
arbitrary code execution
security issues
libvpx
vp8
exploited
vulnerability
threat advisories

0.248 Low

EPSS

Percentile

96.7%

Threat Level Vulnerability Report For a detailed threat advisory, download the pdf file here Summary A zero-day vulnerability, CVE-2023-5217, is actively exploited and has been patched in both Google Chrome and Firefox browsers. CVE-2023-5217 is a Heap buffer overflow vulnerability discovered in the vp8 encoding component of libvpx, which has the potential to allow the execution of arbitrary code on the targeted system. Additionally, Google addressed multiple security issues including CVE-2023-5186, CVE-2023-5187, and CVE-2023-5217. All CVE-2023-5186, CVE-2023-5187 and CVE-2023-5217 are use-after-free flaws and they could also lead to arbitrary code execution. To receive real-time threat advisories, please follow HiveForce Labs on LinkedIn.