Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2jv4-596w-g9hj

Опубликовано: 08 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

In hasAccountsOnAnyUser of DevicePolicyManagerService.java, there is a possible way to add a Device Owner after provisioning due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

In hasAccountsOnAnyUser of DevicePolicyManagerService.java, there is a possible way to add a Device Owner after provisioning due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

EPSS

Процентиль: 37%
0.00158
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 5.5
nvd
2 месяца назад

In hasAccountsOnAnyUser of DevicePolicyManagerService.java, there is a possible way to add a Device Owner after provisioning due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 5.5
fstec
2 месяца назад

Уязвимость компонента Framework операционных систем Android, позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 37%
0.00158
Низкий

7.8 High

CVSS3