HIGH
CVE-2023-33063
CVSS
7.8
KEV
Description
Memory corruption in DSP Services during a remote call from HLOS to DSP.
Summary dbcve.org
Memory corruption vulnerability in DSP (Digital Signal Processor) Services that occurs during remote procedure calls from the HLOS (High Level Operating System) to the DSP subsystem. This could allow an attacker to execute arbitrary code or cause denial of service via corrupted memory operations in the DSP context.
Mitigation
Apply vendor-provided firmware patches for affected Qualcomm Snapdragon/DSP components. Organizations should consult device manufacturers for available updates and prioritize patching mobile/embedded devices with exposed DSP interfaces.
Weakness (CWE)
CWE-416
Use After Free
EPSS Score
0.7%
Probability of exploitation in next 30 days
51.3th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.