PT-2023-17747 · Google · Android

CVE-2023-20959

·

Publicado

2023-03-01

·

Atualizado

2025-02-21

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Android versions Android-13
Description The issue arises from missing permissions checks in the AddSupervisedUserActivity, allowing guest users to start the activity. This could lead to local escalation of privilege without requiring additional execution privileges. User interaction is not necessary for exploitation.
Recommendations For Android version Android-13, consider restricting access to the AddSupervisedUserActivity until a patch is available to prevent local escalation of privilege.

Correção

Missing Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ASB-A-249057848
CVE-2023-20959

Produtos afetados

Android