漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Visteon Infotainment VIP MCU Code Insufficient Validation of Data Authenticity Local Privilege Escalation Vulnerability
Vulnerability Description
Visteon Infotainment VIP MCU Code Insufficient Validation of Data Authenticity Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Visteon Infotainment systems. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the firmware update process of the VIP microcontroller. The process does not properly verify authenticity of the supplied firmware image before programming it into internal memory. An attacker can leverage this vulnerability to escalate privileges execute arbitrary code in the context of the VIP MCU. Was ZDI-CAN-23758.
CVSS Information
N/A
Vulnerability Type
对数据真实性的验证不充分
Vulnerability Title
Visteon Infotainment 数据伪造问题漏洞
Vulnerability Description
Visteon Infotainment是美国伟世通(Visteon)公司的一个汽车信息娱乐系统。 Visteon Infotainment存在数据伪造问题漏洞,该漏洞源于VIP微控制器固件更新过程中对提供的固件映像的真实性验证不足,可能导致本地攻击者在受影响的安装上提升权限执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A