Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c97p-79cx-vqh9

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7

Описание

Race condition in the bindBackupAgent method in the ActivityManagerService in Android 4.4.4 allows local users with adb shell access to execute arbitrary code or any valid package as system by running "pm install" with the target apk, and simultaneously running a crafted script to process logcat's output looking for a dexopt line, which once found should execute bindBackupAgent with the uid member of the ApplicationInfo parameter set to 1000.

Race condition in the bindBackupAgent method in the ActivityManagerService in Android 4.4.4 allows local users with adb shell access to execute arbitrary code or any valid package as system by running "pm install" with the target apk, and simultaneously running a crafted script to process logcat's output looking for a dexopt line, which once found should execute bindBackupAgent with the uid member of the ApplicationInfo parameter set to 1000.

EPSS

Процентиль: 80%
0.01386
Низкий

7 High

CVSS3

Дефекты

CWE-362

Связанные уязвимости

CVSS3: 7
nvd
больше 8 лет назад

Race condition in the bindBackupAgent method in the ActivityManagerService in Android 4.4.4 allows local users with adb shell access to execute arbitrary code or any valid package as system by running "pm install" with the target apk, and simultaneously running a crafted script to process logcat's output looking for a dexopt line, which once found should execute bindBackupAgent with the uid member of the ApplicationInfo parameter set to 1000.

EPSS

Процентиль: 80%
0.01386
Низкий

7 High

CVSS3

Дефекты

CWE-362