CVE-2021-0703
published 2021-10-22CVE-2021-0703: In SecondStageMain of init.cpp, there is a possible use after free due to incorrect shared_ptr usage. This could lead to local escalation of privilege if the…
PriorityP427medium6.8CVSS 3.1
AVPACLPRNUINSUCHIHAH
EPSS
0.12%
2.5th percentile
In SecondStageMain of init.cpp, there is a possible use after free due to incorrect shared_ptr usage. This could lead to local escalation of privilege if the attacker has physical access to the device, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-184569329
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| platform | system_core | >= 11:0 < 11:2021-10-01 | 11:2021-10-01 |
| platform | system_core | >= 12-next:0 < 12-next:2021-10-01 | 12-next:2021-10-01 |
| platform | system_core | >= 12:0 < 12:2021-10-01 | 12:2021-10-01 |
CVSS provenance
nvdv3.16.8MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Android
CVE-2021-0703: Android Security Bulletin 2021-10-01
CVE: CVE-2021-0703
Severity: HIGH
Type: EoP
Affected AOSP versions: 11
References: A-184569329
vendor_android·2021-10-01·CVSS 6.8
CVE-2021-0703 [MEDIUM] CVE-2021-0703: Android Security Bulletin 2021-10-01
CVE: CVE-2021-0703
Severity: HIGH
Type: EoP
Affected AOSP versions: 11
References: A-184569329
Android Security Bulletin 2021-10-01
CVE: CVE-2021-0703
Severity: HIGH
Type: EoP
Affected AOSP versions: 11
References: A-184569329
GHSA
GHSA-r5f5-hqc8-7rx6: In SecondStageMain of init
ghsa_unreviewed·2022-05-24
CVE-2021-0703 [HIGH] CWE-416 GHSA-r5f5-hqc8-7rx6: In SecondStageMain of init
In SecondStageMain of init.cpp, there is a possible use after free due to incorrect shared_ptr usage. This could lead to local escalation of privilege if the attacker has physical access to the device, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-184569329
OSV
CVE-2021-0703: In SecondStageMain of init
osv·2021-10-01
CVE-2021-0703 CVE-2021-0703: In SecondStageMain of init
In SecondStageMain of init.cpp, there is a possible use after free due to incorrect shared_ptr usage. This could lead to local escalation of privilege if the attacker has physical access to the device, with no additional execution privileges needed. User interaction is not needed for exploitation.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-10-22
Published