CVE-2023-40077
published 2023-12-04CVE-2023-40077: In multiple functions of MetaDataBase.cpp, there is a possible UAF write due to a race condition. This could lead to remote escalation of privilege with no…
PriorityP356high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
8.42%
94.4th percentile
In multiple functions of MetaDataBase.cpp, there is a possible UAF write due to a race condition. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| platform | frameworks_av | >= 11:0 < 11:2023-12-01 | 11:2023-12-01 |
| platform | frameworks_av | >= 12:0 < 12:2023-12-01 | 12:2023-12-01 |
| platform | frameworks_av | >= 12L:0 < 12L:2023-12-01 | 12L:2023-12-01 |
| platform | frameworks_av | >= 13:0 < 13:2023-12-01 | 13:2023-12-01 |
| platform | frameworks_av | >= 14-next:0 < 14-next:2023-12-01 | 14-next:2023-12-01 |
| platform | frameworks_av | >= 14:0 < 14:2023-12-01 | 14:2023-12-01 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8m3f-6gqr-5fmr: In multiple functions of MetaDataBase
ghsa_unreviewed·2023-12-05
CVE-2023-40077 [HIGH] CWE-362 GHSA-8m3f-6gqr-5fmr: In multiple functions of MetaDataBase
In multiple functions of MetaDataBase.cpp, there is a possible UAF write due to a race condition. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
OSV
CVE-2023-40077: In multiple functions of MetaDataBase
osv·2023-12-01
CVE-2023-40077 CVE-2023-40077: In multiple functions of MetaDataBase
In multiple functions of MetaDataBase.cpp, there is a possible UAF write due to a race condition. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Android
CVE-2023-40077: Android Security Bulletin 2023-12-01
CVE: CVE-2023-40077
Severity: CRITICAL
Type: EoP
Affected AOSP versions: 11, 12, 12L, 13, 14
References: A-298057
vendor_android·2023-12-01·CVSS 8.1
CVE-2023-40077 [HIGH] CVE-2023-40077: Android Security Bulletin 2023-12-01
CVE: CVE-2023-40077
Severity: CRITICAL
Type: EoP
Affected AOSP versions: 11, 12, 12L, 13, 14
References: A-298057
Android Security Bulletin 2023-12-01
CVE: CVE-2023-40077
Severity: CRITICAL
Type: EoP
Affected AOSP versions: 11, 12, 12L, 13, 14
References: A-298057702
No detection rules found.
No public exploits indexed.
Checkpoint
11th December – Threat Intelligence Report
blogs_checkpoint·2023-12-11
CVE-2023-40088 11th December – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 11th December – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 11th December, please download our Threat_Intelligence Bulletin .
TOP ATTACKS AND BREACHES
The American Greater Richmond Transit Company (GRTC), which provides services for millions of people, has been a victim of cyber-attack that impacted certain applications and parts of the GRTC network. The Play ransomware gang claimed responsibility for the attack.
Check Point Harmony Endpoint and Threat Emulation prov
Bleepingcomputer
December Android updates fix critical zero-click RCE flaw
blogs_bleepingcomputer·2023-12-04·CVSS 8.4
CVE-2023-40088 [HIGH] December Android updates fix critical zero-click RCE flaw
## December Android updates fix critical zero-click RCE flaw
## Sergiu Gatlan
Google announced today that the December 2023 Android security updates tackle 85 vulnerabilities, including a critical severity zero-click remote code execution (RCE) bug.
Tracked as CVE-2023-40088, the zero-click RCE bug was found in Android's System component and doesn't require additional privileges to be exploited.
While the company has yet to reveal if attackers have targeted this security flaw in the wild, threat actors could exploit it to gain arbitrary code execution without user interaction.
"The most severe of these issues is a critical security vulnerability in the System component that could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User int
https://android.googlesource.com/platform/frameworks/av/+/58fd993a89a3a22fa5a4a1a4548125c6783ec80chttps://source.android.com/security/bulletin/2023-12-01https://android.googlesource.com/platform/frameworks/av/+/58fd993a89a3a22fa5a4a1a4548125c6783ec80chttps://source.android.com/security/bulletin/2023-12-01
2023-12-04
Published