CVE-2022-20220
published 2022-07-13CVE-2022-20220: In openFile of CallLogProvider.java, there is a possible permission bypass due to a path traversal error. This could lead to local escalation of privilege with…
PriorityP340high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.18%
7.6th percentile
In openFile of CallLogProvider.java, there is a possible permission bypass due to a path traversal error. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12LAndroid ID: A-219015884
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| msrc | windows_10 | — | — |
| msrc | windows_10_version_1607 | — | — |
| msrc | windows_10_version_1809 | — | — |
| msrc | windows_10_version_20h2 | — | — |
| msrc | windows_10_version_21h1 | — | — |
| msrc | windows_10_version_21h2 | — | — |
| msrc | windows_11_version_21h2 | — | — |
| msrc | windows_8.1 | — | — |
| msrc | windows_rt_8.1 | — | — |
| msrc | windows_server_2012 | — | — |
| msrc | windows_server_2012_r2 | — | — |
| msrc | windows_server_2016 | — | — |
| msrc | windows_server_2019 | — | — |
| msrc | windows_server_2022 | — | — |
| msrc | windows_server_version_20h2 | — | — |
| platform | packages_providers_contactsprovider | >= 12:0 < 12:2022-07-05 | 12:2022-07-05 |
| platform | packages_providers_contactsprovider | >= 12L:0 < 12L:2022-07-05 | 12L:2022-07-05 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vendor_msrc6.7HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-f6hg-99jw-r4ch: In openFile of CallLogProvider
ghsa_unreviewed·2022-07-14
CVE-2022-20220 [HIGH] CWE-22 GHSA-f6hg-99jw-r4ch: In openFile of CallLogProvider
In openFile of CallLogProvider.java, there is a possible permission bypass due to a path traversal error. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12LAndroid ID: A-219015884
OSV
CVE-2022-20220: In openFile of CallLogProvider
osv·2022-07-01
CVE-2022-20220 CVE-2022-20220: In openFile of CallLogProvider
In openFile of CallLogProvider.java, there is a possible permission bypass due to a path traversal error. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.
Microsoft
CERT/CC: CVE-20220-34303 Crypto Pro Boot Loader Bypass
vendor_msrc·2022-08-09·CVSS 6.7
CVE-2022-34303 [MEDIUM] CERT/CC: CVE-20220-34303 Crypto Pro Boot Loader Bypass
CERT/CC: CVE-20220-34303 Crypto Pro Boot Loader Bypass
FAQ: What kind of security feature could be bypassed by successfully exploiting this vulnerability?
An attacker who successfully exploited this vulnerability could bypass Secure Boot.
FAQ: Why are there different security update packages for this CVE?
These are standalone security updates. These packages must be installed in addition to the normal security updates to be protected from this vulnerability.
Are there any prerequisites to these security updates?
These security updates have a Servicing Stack Update prerequisite for specific KB numbers. The packages have a built in pre-requisite logic to ensure the ordering.
Customer should ensure that they have the latest Servicing Stack Update installed before installing these standalone
Android
CVE-2022-20220: Android Security Bulletin 2022-07-01
CVE: CVE-2022-20220
Severity: HIGH
Type: EoP
Affected AOSP versions: 12, 12L
References: A-219015884
vendor_android·2022-07-01·CVSS 7.8
CVE-2022-20220 [HIGH] CVE-2022-20220: Android Security Bulletin 2022-07-01
CVE: CVE-2022-20220
Severity: HIGH
Type: EoP
Affected AOSP versions: 12, 12L
References: A-219015884
Android Security Bulletin 2022-07-01
CVE: CVE-2022-20220
Severity: HIGH
Type: EoP
Affected AOSP versions: 12, 12L
References: A-219015884
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-07-13
Published