CVE-2019-2200
published 2020-02-13CVE-2019-2200: In updatePermissions of PermissionManagerService.java, it may be possible for a malicious app to obtain a custom permission from another app due to a…
PriorityP433high7.3CVSS 3.1
AVLACLPRLUIRSUCHIHAH
EPSS
0.19%
8.7th percentile
In updatePermissions of PermissionManagerService.java, it may be possible for a malicious app to obtain a custom permission from another app due to a permission bypass. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-67319274
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — |
CVSS provenance
nvdv3.17.3HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Android
CVE-2019-2200: Android Security Bulletin 2020-02-01
CVE: CVE-2019-2200
Severity: HIGH
Type: EoP
Affected AOSP versions: 10
References: A-67319274
vendor_android·2020-02-01·CVSS 7.3
CVE-2019-2200 [HIGH] CVE-2019-2200: Android Security Bulletin 2020-02-01
CVE: CVE-2019-2200
Severity: HIGH
Type: EoP
Affected AOSP versions: 10
References: A-67319274
Android Security Bulletin 2020-02-01
CVE: CVE-2019-2200
Severity: HIGH
Type: EoP
Affected AOSP versions: 10
References: A-67319274
Red Hat
hw: Intel SGX information leak
vendor_redhat·2019-11-12·CVSS 4.4
CVE-2019-0117 [MEDIUM] CWE-1220 hw: Intel SGX information leak
hw: Intel SGX information leak
Insufficient access control in protected memory subsystem for Intel(R) SGX for 6th, 7th, 8th, 9th Generation Intel(R) Core(TM) Processor Families; Intel(R) Xeon(R) Processor E3-1500 v5, v6 Families; Intel(R) Xeon(R) E-2100 & E-2200 Processor Families with Intel(R) Processor Graphics may allow a privileged user to potentially enable information disclosure via local access.
A flaw was found in the implementation of SGX around the access control of protected memory. This flaw allows a local attacker of a system with SGX enabled and an affected intel GPU with the ability to execute code to interpret the contents of the SGX protected memory.
Statement: Red Hat Product Security is aware of this issue. Updates will be released as they become available. For additi
Red Hat
hw: Intel GPU blitter manipulation can allow for arbitrary kernel memory write
vendor_redhat·2019-11-12·CVSS 7.8
CVE-2019-0155 [HIGH] CWE-284 hw: Intel GPU blitter manipulation can allow for arbitrary kernel memory write
hw: Intel GPU blitter manipulation can allow for arbitrary kernel memory write
Insufficient access control in a subsystem for Intel (R) processor graphics in 6th, 7th, 8th and 9th Generation Intel(R) Core(TM) Processor Families; Intel(R) Pentium(R) Processor J, N, Silver and Gold Series; Intel(R) Celeron(R) Processor J, N, G3900 and G4900 Series; Intel(R) Atom(R) Processor A and E3900 Series; Intel(R) Xeon(R) Processor E3-1500 v5 and v6, E-2100 and E-2200 Processor Families; Intel(R) Graphics Driver for Windows before 26.20.100.6813 (DCH) or 26.20.100.6812 and before 21.20.x.5077 (aka15.45.5077), i915 Linux Driver for Intel(R) Processor Graphics before versions 5.4-rc7, 5.3.11, 4.19.84, 4.14.154, 4.9.201, 4.4.201 may allow an authenticated user to potentially enable escalation of privileg
GHSA
GHSA-xrjq-qcvc-7j3h: In updatePermissions of PermissionManagerService
ghsa_unreviewed·2022-05-24
CVE-2019-2200 [MEDIUM] GHSA-xrjq-qcvc-7j3h: In updatePermissions of PermissionManagerService
In updatePermissions of PermissionManagerService.java, it may be possible for a malicious app to obtain a custom permission from another app due to a permission bypass. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-67319274
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-02-13
Published