« Volver al listado

CVE-2023-38538

Estado: ModificadaMedia (5)—

A race condition in an event subsystem led to a heap use-after-free issue in established audio/video calls that could have resulted in app termination or unexpected control flow with very low probability.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-38538",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-38538",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-09-19T15:27:40.316899Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "cve-assign@fb.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "HIGH",
          "availabilityImpact": "LOW",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 3.4,
        "exploitabilityScore": 1.6
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "HIGH",
          "availabilityImpact": "LOW",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 3.4,
        "exploitabilityScore": 1.6
      }
    ]
  },
  "affected": [
    {
      "source": "cve-assign@fb.com",
      "affectedData": [
        {
          "vendor": "Facebook",
          "product": "WhatsApp Desktop for Mac",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "2.2338.12",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "vendor": "Facebook",
          "product": "WhatsApp Desktop for Windows",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "2.2320.2",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "vendor": "Facebook",
          "product": "WhatsApp Business for iOS",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "2.23.10.77",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "vendor": "Facebook",
          "product": "WhatsApp for iOS",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "2.23.10.77",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "vendor": "Facebook",
          "product": "WhatsApp Business for Android",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "2.23.10.77",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "vendor": "Facebook",
          "product": "WhatsApp for Android",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "2.23.10.77",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2023-10-04T20:15:10.020",
  "references": [
    {
      "url": "https://www.whatsapp.com/security/advisories/2023/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve-assign@fb.com"
    },
    {
      "url": "https://www.whatsapp.com/security/advisories/2023/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-362"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A race condition in an event subsystem led to a heap use-after-free issue in established audio/video calls that could have resulted in app termination or unexpected control flow with very low probability."
    },
    {
      "lang": "es",
      "value": "Una condición de ejecución en un subsistema de eventos provocó un problema de use-after-free en llamadas de audio/video establecidas que podría haber resultado en la terminación de la aplicación o en un flujo de control inesperado con muy baja probabilidad."
    }
  ],
  "lastModified": "2026-06-17T06:10:41.083",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:whatsapp:whatsapp:*:*:*:*:desktop:windows:*:*",
              "vulnerable": true,
              "matchCriteriaId": "59B97470-3259-479B-A43F-13FAD03299F6",
              "versionEndExcluding": "2.2320.2"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve-assign@fb.com"
}