Impact
The vulnerability stems from improper authentication within Microsoft Authenticator for Android, allowing an unauthorized local attacker to elevate privileges. This flaw enables the attacker to bypass standard security controls and gain elevated access to the device, potentially compromising confidential data, executing privileged actions, and furthering other attacks. The weakness is classified as improper authentication and can lead to unauthorized system access and privilege abuse.
Affected Systems
Microsoft Authenticator for Android is affected. No specific version information is provided, indicating that all released versions prior to the official fix are vulnerable. The issue affects all installations of the app that have not been updated to the patched release.
Risk and Exploitability
With a CVSS score of 8.6 the flaw is considered high severity. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is inferred to be local, requiring the attacker to have physical or otherwise privileged access to the device. Once the flaw is exploited, the attacker can acquire local administrative rights, posing a significant risk to device integrity and confidentiality.
OpenCVE Enrichment