Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r8c4-7j88-47m9

Опубликовано: 02 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 6.2

Описание

In createSessionInternal of PackageInstallerService.java, there is a possible to update a Device Policy Controller (DPC) into an invalid directory due to a path traversal error. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

In createSessionInternal of PackageInstallerService.java, there is a possible to update a Device Policy Controller (DPC) into an invalid directory due to a path traversal error. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

EPSS

Процентиль: 3%
0.00132
Низкий

6.2 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 6.2
nvd
2 месяца назад

In createSessionInternal of PackageInstallerService.java, there is a possible to update a Device Policy Controller (DPC) into an invalid directory due to a path traversal error. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 8.4
fstec
2 месяца назад

Уязвимость метода createSessionInternal класса PackageInstallerService.java компонента Framework операционных систем Android, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 3%
0.00132
Низкий

6.2 Medium

CVSS3

Дефекты

CWE-22