CVE-2021-0398
published 2021-03-10CVE-2021-0398: In bindServiceLocked of ActiveServices.java, there is a possible foreground service launch due to a confused deputy. This could lead to local escalation of…
PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.13%
2.8th percentile
In bindServiceLocked of ActiveServices.java, there is a possible foreground service launch due to a confused deputy. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-173516292
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| platform | frameworks_base | >= 11:0 < 11:2021-03-01 | 11:2021-03-01 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Android
CVE-2021-0398: Android Security Bulletin 2021-03-01
CVE: CVE-2021-0398
Severity: HIGH
Type: EoP
Affected AOSP versions: 11
References: A-173516292
vendor_android·2021-03-01·CVSS 7.8
CVE-2021-0398 [HIGH] CVE-2021-0398: Android Security Bulletin 2021-03-01
CVE: CVE-2021-0398
Severity: HIGH
Type: EoP
Affected AOSP versions: 11
References: A-173516292
Android Security Bulletin 2021-03-01
CVE: CVE-2021-0398
Severity: HIGH
Type: EoP
Affected AOSP versions: 11
References: A-173516292
GHSA
GHSA-3qr5-8x2w-5cvx: In bindServiceLocked of ActiveServices
ghsa_unreviewed·2022-05-24
CVE-2021-0398 [HIGH] GHSA-3qr5-8x2w-5cvx: In bindServiceLocked of ActiveServices
In bindServiceLocked of ActiveServices.java, there is a possible foreground service launch due to a confused deputy. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-173516292
OSV
CVE-2021-0398: In bindServiceLocked of ActiveServices
osv·2021-03-01
CVE-2021-0398 CVE-2021-0398: In bindServiceLocked of ActiveServices
In bindServiceLocked of ActiveServices.java, there is a possible foreground service launch due to a confused deputy. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-03-10
Published