Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-20953
HistoryMar 24, 2023 - 12:00 a.m.

CVE-2023-20953

2023-03-2400:00:00
ubuntu.com
ubuntu.com
8
cve-2023-20953
clipboard listener
privilege escalation
bypass
factory reset protection
android-13
user interaction

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

0.0005 Low

EPSS

Percentile

17.2%

In onPrimaryClipChanged of ClipboardListener.java, there is a possible way
to bypass factory reset protection due to incorrect UI being shown prior to
setup completion. This could lead to local escalation of privilege with no
additional execution privileges needed. User interaction is needed for
exploitation.Product: AndroidVersions: Android-13Android ID: A-251778420

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

0.0005 Low

EPSS

Percentile

17.2%

Related for UB:CVE-2023-20953