| ID |
CVE-2021-39794
|
| Sažetak |
In broadcastPortInfo of AdbService.java, there is a possible way for apps to run code as the shell user, if wireless debugging is enabled, due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12LAndroid ID: A-205836329 |
| Reference |
|
| CVSS |
| Base: | 7.6 |
| Impact: | 10.0 |
| Exploitability: | 4.9 |
|
| Pristup |
| Vektor | Složenost | Autentikacija |
| NETWORK |
HIGH |
NONE |
|
| Impact |
| Povjerljivost | Cjelovitost | Dostupnost |
| COMPLETE |
COMPLETE |
COMPLETE |
|
| CVSS vektor |
AV:N/AC:H/Au:N/C:C/I:C/A:C |
| Zadnje važnije ažuriranje |
19-04-2022 - 18:32 |
| Objavljeno |
12-04-2022 - 17:15 |