CVE-2021-39709
published 2022-03-16CVE-2021-39709: In sendSipAccountsRemovedNotification of SipAccountRegistry.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to…
PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.13%
2.9th percentile
In sendSipAccountsRemovedNotification of SipAccountRegistry.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-208817618
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| platform | packages_services_telephony | >= 12:0 < 12:2022-03-01 | 12:2022-03-01 |
| platform | packages_services_telephony | >= 12L:0 < 12L:2022-03-01 | 12L:2022-03-01 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Android
CVE-2021-39709: Android Security Bulletin 2022-03-01
CVE: CVE-2021-39709
Severity: HIGH
Type: EoP
Affected AOSP versions: 12
References: A-208817618
vendor_android·2022-03-01·CVSS 7.8
CVE-2021-39709 [HIGH] CVE-2021-39709: Android Security Bulletin 2022-03-01
CVE: CVE-2021-39709
Severity: HIGH
Type: EoP
Affected AOSP versions: 12
References: A-208817618
Android Security Bulletin 2022-03-01
CVE: CVE-2021-39709
Severity: HIGH
Type: EoP
Affected AOSP versions: 12
References: A-208817618
GHSA
GHSA-gw9c-6h2r-fxw3: In sendSipAccountsRemovedNotification of SipAccountRegistry
ghsa_unreviewed·2022-03-17
CVE-2021-39709 [HIGH] GHSA-gw9c-6h2r-fxw3: In sendSipAccountsRemovedNotification of SipAccountRegistry
In sendSipAccountsRemovedNotification of SipAccountRegistry.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-208817618
OSV
CVE-2021-39709: In sendSipAccountsRemovedNotification of SipAccountRegistry
osv·2022-03-01
CVE-2021-39709 CVE-2021-39709: In sendSipAccountsRemovedNotification of SipAccountRegistry
In sendSipAccountsRemovedNotification of SipAccountRegistry.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-03-16
Published