CISA adds bugs in Android and Novi Survey to its Known Exploited Vulnerabilities catalog
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-20963 | Local Privilege Escalation in Android Framework (WorkSource Parcel Mismatch) CVE-2023-20963 is a local privilege escalation vulnerability in the Android Framework's WorkSource component, caused by a parcel mismatch (improperly handled parcel data) on devices running Android 11, 12, 12L, and 13. A malicious or compromised app already on the device can trigger the mismatch with no additional execution privileges and no user interaction, making it a low-friction vector once an attacker has any local foothold. Successful exploitation escalates privileges beyond the normal app sandbox - the CVSS 7.8 vector scores high confidentiality, integrity, and availability impact while requiring only low local privileges, indicating substantial system-level access. Any Android device on versions 11 through 13 that has not received the vendor's security patch is potentially affected, which spans a large share of the global smartphone and tablet fleet. The flaw is being actively exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2023-04-13 (EPSS currently estimates a 1.5% probability of exploitation in the next 30 days), and related news coverage - including Google's suspension of the Chinese e-commerce app Pinduoduo over malware - links the exploited bug to a broader malware campaign. Do: Apply the latest Android security updates from your device vendor or OEM as soon as they are issued, prioritizing all devices on Android 11, 12, 12L, or 13 - this is the required action CISA lists for this KEV entry. Until patched, avoid installing apps from untrusted sources, since exploitation requires the attacker to already run code locally on the device. Administrators should inventory Android 11-13 endpoints via MDM/EMM and track the fix by Android bug ID A-220302519. | 7.8 | 1% | KEV |
| mass~1-3+ billion devices (Android 11-13 cover the majority of Google's 3+ billion active Android installs) | |
| CVE-2023-29492 | Unauthenticated Deserialization RCE in 3rd Mill Novi Survey Novi Survey, a survey platform from 3rd Mill, fails to safely handle untrusted deserialization (CWE-94), letting unauthenticated remote attackers execute arbitrary code on the server. Because the flaw is network-reachable and requires no privileges or user interaction (CVSS 9.8), any exposed Novi Survey instance running a version before 8.9.43676 can be targeted directly over HTTP. A successful attacker gains code execution in the context of the service account running the application, though the flaw does not grant access to stored survey or response data. Organizations hosting Novi Survey themselves are affected; the bug was added to CISA's Known Exploited Vulnerabilities catalog on 2023-04-13 following reports of active exploitation, with an EPSS of about 2.7% (85th percentile). Ransomware association is currently unknown, and no public proof-of-concept is available. Do: Upgrade Novi Survey to version 8.9.43676 or later per vendor instructions, prioritizing instances exposed to the internet. In the meantime, restrict network access to the survey application and review service account activity and process logs for signs of compromise, since successful exploitation runs code under that account. Because the flaw does not expose stored survey data, incident review should focus on service-level code execution rather than data access. | 9.8 | 3% | KEV |
| nichelikely hundreds to low thousands of internet-exposed instances (unknown; no public install counts or scan data) |
Full article285 words · extracted from securityaffairs.com · click to collapse

US Cybersecurity and Infrastructure Security Agency (CISA) added Android and Novi Survey flaws to its Known Exploited Vulnerabilities catalog.
U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added the following five new issues to its Known Exploited Vulnerabilities Catalog:
- CVE-2023-20963 – Android Framework Privilege Escalation Vulnerability. Android Framework contains an unspecified vulnerability that allows for privilege escalation after updating an app to a higher Target SDK with no additional execution privileges needed;
- CVE-2023-29492 – Novi Survey Insecure Deserialization Vulnerability. Novi Survey contains an insecure deserialization vulnerability that allows remote attackers to execute code on the server in the context of the service account;
Google addressed the vulnerability CVE-2023-20963 with the release of “The Android Security Bulletin—March 2023” security updates. The bulletin confirmed that “there are indications that CVE-2023-20963 may be under limited, targeted exploitation.”
According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.
Experts recommend also private organizations review the Catalog and address the vulnerabilities in their infrastructure.
CISA orders federal agencies to fix this flaw by May 4, 2023.
Please vote for Security Affairs (https://securityaffairs.com/) as the best European Cybersecurity Blogger Awards 2022 – VOTE FOR YOUR WINNERS
Vote for me in the sections:
- The Teacher – Most Educational Blog
- The Entertainer – Most Entertaining Blog
- The Tech Whizz – Best Technical Blog
- Best Social Media Account to Follow (@securityaffairs)
Please nominate Security Affairs as your favorite blog.
Nominate here: https://docs.google.com/forms/d/e/1FAIpQLSfaFMkrMlrLhOBsRPKdv56Y4HgC88Bcji4V7OCxCm_OmyPoLw/viewform
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, CISA)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/144822/security/android-flaws-cisa-known-exploited-vulnerabilities-catalog.html