PT-2022-20264 · Unknown · Personamanagerservice
CVE-2022-30727
·
Published
2022-06-07
·
Updated
2022-06-11
CVSS v3.1
6.2
Medium
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
PersonaManagerService versions prior to SMR Jun-2022 Release 1
Description
The issue is related to improper handling of insufficient permissions in the
addAppPackageNameToAllowList function within the PersonaManagerService. This allows local attackers to modify certain setting values in the workspace.Recommendations
For versions prior to SMR Jun-2022 Release 1, update to the SMR Jun-2022 Release 1 or later to resolve the issue.
Fix
Improper Handling of Exceptional Conditions
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Personamanagerservice