CVE-2023-5217
Google Chromium libvpx Heap Buffer Overflow Vulnerability
- 대응 우선순위
- 최우선
- CVSS
- 8.8
- EPSS
- 34.4% 백분위 98.2% · 2026.06.27 기준
- CISA KEV
- 등록
- 조치 기한
- 2023.10.23
- 공개일
- 2023.09.29
CISA KEV에 등록된 실제 악용 확인 취약점
Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
공급사 Google
제품 Chromium libvpx
영향 버전 117.0.5938.132, 1.13.1, < 1.13.1, 116.0.1938.98, 117.0.2045.47, 116.0.5845.229, < 115.3.1, < 118.0.1, < 118.1, 37, 38, 39, 10.0, 11.0, 12.0, >= 17.0 < 17.0.3, 16.7, < 117.0.5938.132, 9.0
수정 버전 1.13.1, 115.3.1, 118.0.1, 118.1, 17.0.3, 117.0.5938.132
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
조치 기한: 2023.10.23CVSS 벡터 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE CWE-787
KEV 등록일 2023.10.02
랜섬웨어 캠페인 사용 미확인
CISA 비고 https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop_27.html; https://nvd.nist.gov/vuln/detail/CVE-2023-5217
EPSS 데이터 기준일 2026.06.27