PT-2023-7500 · Microsoft · Azure Rtos Usbx

Published

2023-11-17

·

Updated

2025-10-27

·

CVE-2023-48698

CVSS v3.1

6.8

Medium

VectorAV:P/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Azure RTOS USBX versions prior to 6.3.0
Description The issue is related to expired pointer dereference vulnerabilities in Azure RTOS USBX, which can lead to remote code execution. The affected components include functions and processes in the host stack and host classes, related to device linked classes, GSER, and HID. An attacker can exploit this issue due to insufficient checking of exceptional states resulting from dereferencing an expired pointer.
Recommendations For Azure RTOS USBX versions prior to 6.3.0, upgrade to release 6.3.0 to resolve the issue. As a temporary workaround, consider restricting access to the GSER and HID interfaces in the USB host until the update is applied. Avoid using the affected functions and processes in the host stack and host classes related to device linked classes until the issue is resolved.

Exploit

Fix

RCE

Improper Check for Exceptional Conditions

Weakness Enumeration

Related Identifiers

BDU:2023-08545
CVE-2023-48698
GHSA-GRHP-F66Q-X857

Affected Products

Azure Rtos Usbx