Lucene search

K
cvelistGoogle_androidCVELIST:CVE-2024-0047
HistoryMar 11, 2024 - 4:35 p.m.

CVE-2024-0047

2024-03-1116:35:22
google_android
www.cve.org
5
cve-2024-0047
writeuserlp
device policies
logic error
local denial of service
deserialization
reboot
execution privileges

AI Score

6.6

Confidence

High

EPSS

0

Percentile

15.5%

In writeUserLP of UserManagerService.java, device policies are serialized with an incorrect tag due to a logic error in the code. This could lead to local denial of service when policies are deserialized on reboot with no additional execution privileges needed. User interaction is not needed for exploitation.

CNA Affected

[
  {
    "vendor": "Google",
    "product": "Android",
    "versions": [
      {
        "version": "14",
        "status": "affected"
      }
    ],
    "defaultStatus": "unaffected"
  }
]

AI Score

6.6

Confidence

High

EPSS

0

Percentile

15.5%

Related for CVELIST:CVE-2024-0047