cbcvebase.
CVE-2022-20245
published 2022-08-11

CVE-2022-20245: In WindowManager, there is a possible method to create a recording of the lock screen due to an insecure default value. This could lead to local information…

PriorityP44low2.4CVSS 3.1
AVPACLPRNUINSUCLINAN
EPSS
0.13%
2.9th percentile
In WindowManager, there is a possible method to create a recording of the lock screen due to an insecure default value. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-215005011

Affected

4 ranges
VendorProductVersion rangeFixed in
googleandroid
googleandroid
imagemagickimagemagick>= 0 < 8:6.9.10.23+dfsg-2.1ubuntu11.4+esm18:6.9.10.23+dfsg-2.1ubuntu11.4+esm1
imagemagickimagemagick>= 0 < 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.1+esm18:6.9.11.60+dfsg-1.3ubuntu0.22.04.1+esm1

CVSS provenance

nvdv3.12.4LOWCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
osv5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.