CVE-2022-39108
published 2022-10-14CVE-2022-39108: In Music service, there is a missing permission check. This could lead to elevation of privilege in Music service with no additional execution privileges…
PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.15%
5.1th percentile
In Music service, there is a missing permission check. This could lead to elevation of privilege in Music service with no additional execution privileges needed.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| unisoc_technologies_co_ltd | sc9863a_sc9832e_sc7731e_t610_t310_t606_t760_t610_t618_t606_t612_t616_t760_t770_t | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Unisoc S8000 Music Service permission (EUVD-2022-41654)
vuldb·2026-06-27·CVSS 7.8
CVE-2022-39108 [HIGH] Unisoc S8000 Music Service permission (EUVD-2022-41654)
A vulnerability was found in Unisoc SC9863A, SC9832E, SC7731E, T610, T310, T606, T760, T610, T618, T606, T612, T616, T760, T770, T820 and S8000. It has been rated as critical. This impacts an unknown function of the component Music Service. Performing a manipulation results in permission issues.
This vulnerability is known as CVE-2022-39108. Attacking locally is a requirement. No exploit is available.
GHSA
GHSA-2crw-c3p5-4j2g: In Music service, there is a missing permission check
ghsa_unreviewed·2022-10-15
CVE-2022-39108 [HIGH] CWE-862 GHSA-2crw-c3p5-4j2g: In Music service, there is a missing permission check
In Music service, there is a missing permission check. This could lead to elevation of privilege in Music service with no additional execution privileges needed.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-10-14
Published