Confused Deputy Vulnerability in fixUpIncomingShortcutInfo of ShortcutService.java Allows Unauthorized Image Viewing

Confused Deputy Vulnerability in fixUpIncomingShortcutInfo of ShortcutService.java Allows Unauthorized Image Viewing

CVE-2023-45774 · HIGH Severity

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In fixUpIncomingShortcutInfo of ShortcutService.java, there is a possible way to view another user's image due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Learn more about our User Device Pen Test.