Lucene search

K
nvd[email protected]NVD:CVE-2024-0021
HistoryFeb 16, 2024 - 8:15 p.m.

CVE-2024-0021

2024-02-1620:15:47
web.nvd.nist.gov
logic error
local escalation
notification listener

6.7 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.2%

In onCreate of NotificationAccessConfirmationActivity.java, there is a possible way for an app in the work profile to enable notification listener services due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

6.7 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.2%

Related for NVD:CVE-2024-0021