Lucene search

K
cvelistGoogle_androidCVELIST:CVE-2023-35677
HistorySep 11, 2023 - 8:09 p.m.

CVE-2023-35677

2023-09-1120:09:54
google_android
www.cve.org
1
deviceadminadd
oncreate
local denial of service
missing permission check
factory reset
continuous locking
no user interaction

0.0004 Low

EPSS

Percentile

5.1%

In onCreate of DeviceAdminAdd.java, there is a possible way to forcibly add a device admin due to a missing permission check. This could lead to local denial of service (factory reset or continuous locking) with no additional execution privileges needed. User interaction is not needed for exploitation.

CNA Affected

[
  {
    "vendor": "Google",
    "product": "Android",
    "versions": [
      {
        "version": "13",
        "status": "affected"
      },
      {
        "version": "12L",
        "status": "affected"
      },
      {
        "version": "12",
        "status": "affected"
      },
      {
        "version": "11",
        "status": "affected"
      }
    ],
    "defaultStatus": "unaffected"
  }
]

0.0004 Low

EPSS

Percentile

5.1%

Related for CVELIST:CVE-2023-35677