Exploitation Summary
EIP tracks 1 public exploit for CVE-2023-40084. PoCs published by Trinadh465.
AI-analyzed exploit summary This repository contains functional BPF (eBPF) exploit code targeting CVE-2023-40084, a vulnerability in Android's netd component. The code includes BPF programs for NAT64 translation and network statistics, demonstrating the vulnerability in the context of packet processing.
Description
In run of MDnsSdListener.cpp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Exploits (1)
This repository contains functional BPF (eBPF) exploit code targeting CVE-2023-40084, a vulnerability in Android's netd component. The code includes BPF programs for NAT64 translation and network statistics, demonstrating the vulnerability in the context of packet processing.
References (2)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H