CVE-2023-20911
published 2023-03-24CVE-2023-20911: In addPermission of PermissionManagerServiceImpl.java , there is a possible failure to persist permission settings due to resource exhaustion. This could lead…
PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.18%
7.7th percentile
In addPermission of PermissionManagerServiceImpl.java , there is a possible failure to persist permission settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-242537498
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| platform | frameworks_base | >= 11:0 < 11:2023-03-01 | 11:2023-03-01 |
| platform | frameworks_base | >= 12:0 < 12:2023-03-01 | 12:2023-03-01 |
| platform | frameworks_base | >= 12L:0 < 12L:2023-03-01 | 12L:2023-03-01 |
| platform | frameworks_base | >= 13-next:0 < 13-next:2023-03-01 | 13-next:2023-03-01 |
| platform | frameworks_base | >= 13:0 < 13:2023-03-01 | 13:2023-03-01 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xfgj-mmw9-2x4f: In addPermission of PermissionManagerServiceImpl
ghsa_unreviewed·2023-03-24
CVE-2023-20911 [HIGH] CWE-400 GHSA-xfgj-mmw9-2x4f: In addPermission of PermissionManagerServiceImpl
In addPermission of PermissionManagerServiceImpl.java , there is a possible failure to persist permission settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-242537498
OSV
CVE-2023-20911: In addPermission of PermissionManagerServiceImpl
osv·2023-03-01
CVE-2023-20911 CVE-2023-20911: In addPermission of PermissionManagerServiceImpl
In addPermission of PermissionManagerServiceImpl.java , there is a possible failure to persist permission settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Android
CVE-2023-20911: Android Security Bulletin 2023-03-01
CVE: CVE-2023-20911
Severity: HIGH
Type: EoP
Affected AOSP versions: 11, 12, 12L, 13
References: A-242537498
vendor_android·2023-03-01·CVSS 7.8
CVE-2023-20911 [HIGH] CVE-2023-20911: Android Security Bulletin 2023-03-01
CVE: CVE-2023-20911
Severity: HIGH
Type: EoP
Affected AOSP versions: 11, 12, 12L, 13
References: A-242537498
Android Security Bulletin 2023-03-01
CVE: CVE-2023-20911
Severity: HIGH
Type: EoP
Affected AOSP versions: 11, 12, 12L, 13
References: A-242537498
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-03-24
Published