Lucene search

K
cvelistGoogle_androidCVELIST:CVE-2023-20959
HistoryMar 24, 2023 - 12:00 a.m.

CVE-2023-20959

2023-03-2400:00:00
google_android
www.cve.org
android
addsuperviseduseractivity
local privilege escalation

0.0004 Low

EPSS

Percentile

5.1%

In AddSupervisedUserActivity, guest users are not prevented from starting the activity due to missing permissions checks. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-249057848

CNA Affected

[
  {
    "vendor": "n/a",
    "product": "Android",
    "versions": [
      {
        "version": "Android-13",
        "status": "affected"
      }
    ]
  }
]

0.0004 Low

EPSS

Percentile

5.1%

Related for CVELIST:CVE-2023-20959