CVE-2022-39883
published 2022-11-09CVE-2022-39883: Improper authorization vulnerability in StorageManagerService prior to SMR Nov-2022 Release 1 allows local attacker to call privileged API.
PriorityP336high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.08%
0.3th percentile
Improper authorization vulnerability in StorageManagerService prior to SMR Nov-2022 Release 1 allows local attacker to call privileged API.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| samsung_mobile | samsung_mobile_devices | >= Q(10), R(11), S(12) < SMR Nov-2022 Release 1 | SMR Nov-2022 Release 1 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Samsung Smart Phone StorageManagerService improper authorization (EUVD-2022-42328)
vuldb·2026-07-07·CVSS 7.8
CVE-2022-39883 [HIGH] Samsung Smart Phone StorageManagerService improper authorization (EUVD-2022-42328)
A vulnerability has been found in Samsung Smart Phone and classified as critical. This affects an unknown part of the component StorageManagerService. This manipulation causes improper authorization.
This vulnerability is handled as CVE-2022-39883. It is possible to launch the attack on the local host. There is not any exploit available.
The affected component should be upgraded.
GHSA
GHSA-67vh-5v34-43vx: Improper authorization vulnerability in StorageManagerService prior to SMR Nov-2022 Release 1 allows local attacker to call privileged API
ghsa_unreviewed·2022-11-10
CVE-2022-39883 [HIGH] CWE-285 GHSA-67vh-5v34-43vx: Improper authorization vulnerability in StorageManagerService prior to SMR Nov-2022 Release 1 allows local attacker to call privileged API
Improper authorization vulnerability in StorageManagerService prior to SMR Nov-2022 Release 1 allows local attacker to call privileged API.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-11-09
Published