In writeUserLP of UserManagerService.java, device policies are serialized with an incorrect tag due to a logic error in the code. This could lead to local denial of service when policies are deserialized on reboot with no additional execution privileges needed. User interaction is not needed for exploitation.
Metrics
Affected Vendors & Products
References
History
Fri, 22 Nov 2024 12:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Google
Google android |
|
Weaknesses | NVD-CWE-noinfo | |
CPEs | cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:* | |
Vendors & Products |
Google
Google android |
|
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: google_android
Published: 2024-03-11T16:35:22.043Z
Updated: 2024-08-01T17:41:15.915Z
Reserved: 2023-11-16T22:59:24.732Z
Link: CVE-2024-0047
Vulnrichment
Updated: 2024-08-01T17:41:15.915Z
NVD
Status : Analyzed
Published: 2024-03-11T17:15:45.620
Modified: 2024-11-21T21:26:15.987
Link: CVE-2024-0047
Redhat
No data.