SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-0247

A local attacker could modify objects in the VMO that they do not have permission to.

MEDIUM 5.5EPSS 0.08%

Does this matter?

Lower severity and a low EPSS score (0.08%). Track it; it rarely justifies an emergency change on its own.

Description

An issue exists in Fuchsia where VMO data can be modified through access to copy-on-write snapshots. A local attacker could modify objects in the VMO that they do not have permission to. We recommend upgrading past commit d97c05d2301799ed585620a9c5c739d36e7b5d3d or any of the listed versions.

CVSS 3.1
5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
EPSS
0.08% probability · 0th percentile
CISA KEV
Not listed
Weakness
CWE-732
Affected
google/fuchsia
Source
cve-coordination@google.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.