CVE-2023-24923 is an information disclosure vulnerability affecting Microsoft OneDrive for Android. This medium-severity flaw (CVSS 5.5) requires user interaction (UI:R) and local access (AV:L) to exploit, potentially leading to high confidentiality impact (C:H) by revealing sensitive information. While not currently listed on the KEV catalog or Hot List, there is no public exploit code available (Metasploit, Nuclei, ExploitDB: None), and community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 6.73CPE matchmatch criteria | cpe:2.3:a:microsoft:onedrive:*:*:*:*:*:android:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.