cbcvebase.
CVE-2022-20128
published 2022-06-01

CVE-2022-20128: In finishLsImpl of file_sync_client.cpp, there is a possible way to access host's files due to a path traversal error. This could lead to local escalation of…

In finishLsImpl of file_sync_client.cpp, there is a possible way to access host's files due to a path traversal error. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Affected

5 ranges
VendorProductVersion rangeFixed in
platformpackages_modules_adb>= 12:0 < 12:2022-06-0112:2022-06-01
platformpackages_modules_adb>= 12L-next:0 < 12L-next:2022-06-0112L-next:2022-06-01
platformpackages_modules_adb>= 12L:0 < 12L:2022-06-0112L:2022-06-01
platformsystem_core>= 10:0 < 10:2022-06-0110:2022-06-01
platformsystem_core>= 11:0 < 11:2022-06-0111:2022-06-01
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.