Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mhh5-fmpv-m2jw

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

In the AIBinder_Class constructor of ibinder.cpp, there is a possible arbitrary code execution due to uninitialized data. This could lead to local escalation of privilege if a process were using libbinder_ndk in a vulnerable way with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-10Android ID: A-161812320

In the AIBinder_Class constructor of ibinder.cpp, there is a possible arbitrary code execution due to uninitialized data. This could lead to local escalation of privilege if a process were using libbinder_ndk in a vulnerable way with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-10Android ID: A-161812320

EPSS

Процентиль: 3%
0.00015
Низкий

Дефекты

CWE-665

Связанные уязвимости

CVSS3: 7.8
nvd
около 5 лет назад

In the AIBinder_Class constructor of ibinder.cpp, there is a possible arbitrary code execution due to uninitialized data. This could lead to local escalation of privilege if a process were using libbinder_ndk in a vulnerable way with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-10Android ID: A-161812320

EPSS

Процентиль: 3%
0.00015
Низкий

Дефекты

CWE-665