← volver
CVE-2023-21270

CVE-2023-21270

CVSS 7.8 HIGHEPSS 0.1%CWE-276
Vexday Risk Score
21Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 7.8EPSS 0.1%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
19 nov 2024Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
In restorePermissionState of PermissionManagerServiceImpl.java, there is a possible way for an app to keep permissions that should be revoked due to incorrect permission flags cleared during an update. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Productos afectados
Google · Andrioid

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →