CVE-2022-24480
published 2022-12-13CVE-2022-24480: Outlook for Android Elevation of Privilege Vulnerability
PriorityP425medium6.3CVSS 3.1
AVPACHPRLUINSUCHIHAH
EPSS
0.54%
41.7th percentile
Outlook for Android Elevation of Privilege Vulnerability
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_outlook_for_android | >= 1.0 < Publication | Publication |
| msrc | microsoft_outlook_for_android | — | — |
CVSS provenance
nvdv3.16.3MEDIUMCVSS:3.1/AV:P/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_msrc6.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mjqr-f43r-5649: Outlook for Android Elevation of Privilege Vulnerability
ghsa_unreviewed·2022-12-13
CVE-2022-24480 [MEDIUM] GHSA-mjqr-f43r-5649: Outlook for Android Elevation of Privilege Vulnerability
Outlook for Android Elevation of Privilege Vulnerability.
Microsoft
Outlook for Android Elevation of Privilege Vulnerability
vendor_msrc·2022-12-13·CVSS 6.3
CVE-2022-24480 [MEDIUM] Outlook for Android Elevation of Privilege Vulnerability
Outlook for Android Elevation of Privilege Vulnerability
FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?
Successful exploitation of this vulnerability requires an attacker to physically access the target device. To gain access, an attacker must acquire the device after being unlocked by a legitimate user (target of opportunity) or possess the ability to pass device authentication or password protection mechanisms.
FAQ: According to the CVSS metric, privileges required is low (PR:L). What does that mean for this vulnerability?
Modern mobile devices include authentication or password protection mechanisms which an attacker must be able to satisfy before gaining access to the target device.
FAQ: What privileges could be g
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-12-13
Published