In getRegistration of RemoteProvisioningService.java, there is a possible way to permanently disable the AndroidKeyStore key generation feature by updating the attestation keys of all installed apps due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
Metrics
Affected Vendors & Products
References
History
Tue, 17 Dec 2024 19:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Google
Google android |
|
Weaknesses | NVD-CWE-noinfo | |
CPEs | cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:* | |
Vendors & Products |
Google
Google android |
Mon, 04 Nov 2024 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-120 | |
Metrics |
cvssV3_1
|
Wed, 11 Sep 2024 14:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 11 Sep 2024 00:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | In getRegistration of RemoteProvisioningService.java, there is a possible way to permanently disable the AndroidKeyStore key generation feature by updating the attestation keys of all installed apps due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. | |
References |
|

Status: PUBLISHED
Assigner: google_android
Published:
Updated: 2024-11-04T17:23:40.752Z
Reserved: 2024-07-08T18:54:48.877Z
Link: CVE-2024-40659

Updated: 2024-09-11T13:57:19.589Z

Status : Analyzed
Published: 2024-09-11T00:15:11.473
Modified: 2024-12-17T19:07:45.260
Link: CVE-2024-40659

No data.