CVE-2022-39884
published 2022-11-09CVE-2022-39884: Improper access control vulnerability in IImsService prior to SMR Nov-2022 Release 1 allows local attacker to access to Call information.
PriorityP48low3.3CVSS 3.1
AVLACLPRLUINSUCLINAN
EPSS
0.08%
0.3th percentile
Improper access control vulnerability in IImsService prior to SMR Nov-2022 Release 1 allows local attacker to access to Call information.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| samsung_mobile | samsung_mobile_devices | >= Q(10), R(11), S(12) < SMR Nov-2022 Release 1 | SMR Nov-2022 Release 1 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Samsung Smart Phone IImsService access control (EUVD-2022-42329)
vuldb·2026-07-07·CVSS 3.3
CVE-2022-39884 [LOW] Samsung Smart Phone IImsService access control (EUVD-2022-42329)
A vulnerability was found in Samsung Smart Phone and classified as critical. This vulnerability affects unknown code of the component IImsService. Such manipulation leads to improper access controls.
This vulnerability is uniquely identified as CVE-2022-39884. Local access is required to approach this attack. No exploit exists.
It is suggested to upgrade the affected component.
GHSA
GHSA-p2vq-m3jx-j3g2: Improper access control vulnerability in IImsService prior to SMR Nov-2022 Release 1 allows local attacker to access to Call information
ghsa_unreviewed·2022-11-10
CVE-2022-39884 [LOW] GHSA-p2vq-m3jx-j3g2: Improper access control vulnerability in IImsService prior to SMR Nov-2022 Release 1 allows local attacker to access to Call information
Improper access control vulnerability in IImsService prior to SMR Nov-2022 Release 1 allows local attacker to access to Call information.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-11-09
Published