Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-21254
HistoryJul 13, 2023 - 12:15 a.m.

Code injection

2023-07-1300:15:00
PRIOn knowledge base
www.prio-n.com
4
code injection
logic error
onetimepermissionusermanager
local privilege escalation
user interaction

0.0004 Low

EPSS

Percentile

5.1%

In getCurrentState of OneTimePermissionUserManager.java, there is a possible way to hold one-time permissions after the app is being killed due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CPENameOperatorVersion
androideq13.0

0.0004 Low

EPSS

Percentile

5.1%

Related for PRION:CVE-2023-21254