Critical Vulnerability in ISP Allows Local Privilege Escalation without User Interaction

Critical Vulnerability in ISP Allows Local Privilege Escalation without User Interaction

CVE-2023-20721 · MEDIUM Severity

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In isp, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07162155; Issue ID: ALPS07162155.

Learn more about our User Device Pen Test.