Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-14220

Опубликовано: 24 сент. 2019
Источник: nvd
CVSS3: 6.5
CVSS2: 4.9
EPSS Низкий

Описание

An issue was discovered in BlueStacks 4.110 and below on macOS and on 4.120 and below on Windows. BlueStacks employs Android running in a virtual machine (VM) to enable Android apps to run on Windows or MacOS. Bug is in a local arbitrary file read through a system service call. The impacted method runs with System admin privilege and if given the file name as parameter returns you the content of file. A malicious app using the affected method can then read the content of any system file which it is not authorized to read

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:a:bluestacks:bluestacks:*:*:*:*:*:*:*:*
Версия до 4.120 (включая)
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Конфигурация 2

Одновременно

cpe:2.3:a:bluestacks:bluestacks:*:*:*:*:*:*:*:*
Версия до 4.110 (включая)
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*

EPSS

Процентиль: 78%
0.01152
Низкий

6.5 Medium

CVSS3

4.9 Medium

CVSS2

Дефекты

CWE-269

Связанные уязвимости

CVSS3: 6.5
github
больше 3 лет назад

An issue was discovered in BlueStacks 4.110 and below on macOS and on 4.120 and below on Windows. BlueStacks employs Android running in a virtual machine (VM) to enable Android apps to run on Windows or MacOS. Bug is in a local arbitrary file read through a system service call. The impacted method runs with System admin privilege and if given the file name as parameter returns you the content of file. A malicious app using the affected method can then read the content of any system file which it is not authorized to read

EPSS

Процентиль: 78%
0.01152
Низкий

6.5 Medium

CVSS3

4.9 Medium

CVSS2

Дефекты

CWE-269