CVE-2019-2114
published 2019-10-11CVE-2019-2114: In the default privileges of NFC, there is a possible local bypass of user interaction requirements on package installation due to a default permission. This…
PriorityP335high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.23%
14.0th percentile
In the default privileges of NFC, there is a possible local bypass of user interaction requirements on package installation due to a default permission. This could lead to local escalation of privilege by installing an application with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9Android ID: A-123700348
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.04.4MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jv5m-xj7m-mx82: In the default privileges of NFC, there is a possible local bypass of user interaction requirements on package installation due to a default permissio
ghsa_unreviewed·2022-05-24
CVE-2019-2114 [HIGH] CWE-276 GHSA-jv5m-xj7m-mx82: In the default privileges of NFC, there is a possible local bypass of user interaction requirements on package installation due to a default permissio
In the default privileges of NFC, there is a possible local bypass of user interaction requirements on package installation due to a default permission. This could lead to local escalation of privilege by installing an application with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9Android ID: A-123700348
Android
CVE-2019-2114: Android Security Bulletin 2019-10-01
CVE: CVE-2019-2114
Severity: HIGH
Type: EoP
Affected AOSP versions: 8
vendor_android·2019-10-01·CVSS 7.8
CVE-2019-2114 [HIGH] CVE-2019-2114: Android Security Bulletin 2019-10-01
CVE: CVE-2019-2114
Severity: HIGH
Type: EoP
Affected AOSP versions: 8
Android Security Bulletin 2019-10-01
CVE: CVE-2019-2114
Severity: HIGH
Type: EoP
Affected AOSP versions: 8.0, 8.1, 9
References: A-123700348
[2]
No detection rules found.
No public exploits indexed.
Trendmicro
Amazon Echo Hacked; Ransomeware Attacks
blogs_trendmicro·2019-11-08
Amazon Echo Hacked; Ransomeware Attacks
Exploits & Vulnerabilities
# Amazon Echo Hacked; Ransomeware Attacks
Learn about a ransomware that is attacking Spanish companies and how nearly 50 adware apps were found on Google Play. Also, read about how an Amazon Echo was hacked on the first day of Pwn2Own Tokyo 2019.
By: Jon Clay
2019/11/08
Read time: ( words)
Save to Folio
Welcome to our weekly roundup, where we share what you need to know about the cybersecurity news and events that happened over the past few days. This week, learn about a ransomware that is attacking Spanish companies and how nearly 50 adware apps were found on Google Play. Also, read about how an Amazon Echo was hacked on the first day of Pwn2Own Tokyo 2019.
Read on:
#### Facebook Portal Survives Pwn2Own Hacking Contest, Amazon Echo Got Hacked
Amazon Ech
Trendmicro
Amazon Echo Hacked; Ransomeware Attacks
blogs_trendmicro·2019-11-08
Amazon Echo Hacked; Ransomeware Attacks
Exploits & Vulnerabilities
# Amazon Echo Hacked; Ransomeware Attacks
Learn about a ransomware that is attacking Spanish companies and how nearly 50 adware apps were found on Google Play. Also, read about how an Amazon Echo was hacked on the first day of Pwn2Own Tokyo 2019.
By: Jon Clay
Nov 08, 2019
Read time: ( words)
Save to Folio
Welcome to our weekly roundup, where we share what you need to know about the cybersecurity news and events that happened over the past few days. This week, learn about a ransomware that is attacking Spanish companies and how nearly 50 adware apps were found on Google Play. Also, read about how an Amazon Echo was hacked on the first day of Pwn2Own Tokyo 2019.
Read on:
#### Facebook Portal Survives Pwn2Own Hacking Contest, Amazon Echo Got Hacked
Amazon E
https://source.android.com/security/bulletin/2019-10-01https://wwws.nightwatchcybersecurity.com/2019/10/24/nfc-beaming-bypasses-security-controls-in-android-cve-2019-2114/https://source.android.com/security/bulletin/2019-10-01https://wwws.nightwatchcybersecurity.com/2019/10/24/nfc-beaming-bypasses-security-controls-in-android-cve-2019-2114/
2019-10-11
Published