CVE-2023-20963 is a local escalation of privilege vulnerability in Android's WorkSource component, affecting Android versions 11 through 13. This flaw, stemming from a parcel mismatch (CWE-295), allows an attacker to gain elevated privileges without user interaction or additional execution permissions. Rated with a CVSS score of 7.8 (HIGH), it poses a significant risk due to its low attack complexity and high impact on confidentiality, integrity, and availability. The vulnerability is actively exploited in the wild, as confirmed by its presence in CISA's KEV catalog, and has garnered substantial media attention and community discussion, despite the lack of public exploit code on platforms like Metasploit or ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
11.0CPE matchmatch criteria | cpe:2.3:o:google:android:11.0:*:*:*:*:*:*:* | ||
12.0CPE matchmatch criteria | cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:* | ||
12.1CPE matchmatch criteria | cpe:2.3:o:google:android:12.1:*:*:*:*:*:*:* | ||
13.0CPE matchmatch criteria | cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.