Memory Management Vulnerability in Bitcoin Core by Bitcoin.org
CVE-2023-37192

7.5HIGH

Key Information:

Vendor

Bitcoin

Vendor
CVE Published:
7 July 2023

What is CVE-2023-37192?

The vulnerability in Bitcoin Core v22 involves critical memory management and protection flaws that could be exploited by attackers. These flaws enable malicious actors to modify the sending address stored in the application's memory, which can result in unauthorized redirection of Bitcoin transactions to their own wallets. This poses a significant risk to users, as it potentially compromises the integrity of transactions initiated through the app, allowing hackers to redirect funds without user consent.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.