CVE-2022-20423 - CERT CVE
ID CVE-2022-20423
Sažetak In rndis_set_response of rndis.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege if a malicious USB device is attached with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-239842288References: Upstream kernel
Reference
CVSS
Base: 4.6
Impact: 3.6
Exploitability:0.9
Pristup
VektorSloženostAutentikacija
PHYSICAL LOW -
Impact
PovjerljivostCjelovitostDostupnost
HIGH NONE NONE
CVSS vektor CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Zadnje važnije ažuriranje 13-10-2022 - 02:51
Objavljeno 11-10-2022 - 20:15