In getRegistration of RemoteProvisioningService.java, there is a possible way to permanently disable the AndroidKeyStore key generation feature by updating the attestation keys of all installed apps due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
Metrics
Affected Vendors & Products
References
History
Tue, 17 Dec 2024 19:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Google
Google android |
|
Weaknesses | NVD-CWE-noinfo | |
CPEs | cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:* | |
Vendors & Products |
Google
Google android |
Mon, 04 Nov 2024 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-120 | |
Metrics |
cvssV3_1
|
Wed, 11 Sep 2024 14:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 11 Sep 2024 00:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | In getRegistration of RemoteProvisioningService.java, there is a possible way to permanently disable the AndroidKeyStore key generation feature by updating the attestation keys of all installed apps due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. | |
References |
|
MITRE
Status: PUBLISHED
Assigner: google_android
Published: 2024-09-11T00:09:19.421Z
Updated: 2024-11-04T17:23:40.752Z
Reserved: 2024-07-08T18:54:48.877Z
Link: CVE-2024-40659
Vulnrichment
Updated: 2024-09-11T13:57:19.589Z
NVD
Status : Analyzed
Published: 2024-09-11T00:15:11.473
Modified: 2024-12-17T19:07:45.260
Link: CVE-2024-40659
Redhat
No data.