CVE-2023-29727
The Call Blocker application 6.6.3 for Android allows unauthorized applications to use exposed components to delete data stored in its database that is related to user privacy settings and affects the implementation of the normal functionality of the…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.21%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The Call Blocker application 6.6.3 for Android allows unauthorized applications to use exposed components to delete data stored in its database that is related to user privacy settings and affects the implementation of the normal functionality of the application. An attacker can use this to cause an escalation of privilege attack.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.21% probability · 67th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-922
- Affected
- applika/call blocker
- Source
- cve@mitre.org
References
- https://github.com/LianKee/SO-CVEs/blob/main/CVEs/CVE-2023-29727/CVE%20detail.mdExploit, Third Party Advisory
- https://play.google.com/store/apps/details?id=com.cuiet.blockCallsProduct
- https://www.call-blocker.info/Product
- https://github.com/LianKee/SO-CVEs/blob/main/CVEs/CVE-2023-29727/CVE%20detail.mdExploit, Third Party Advisory
- https://play.google.com/store/apps/details?id=com.cuiet.blockCallsProduct
- https://www.call-blocker.info/Product
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.