CVE-2024-0019
published 2024-02-16CVE-2024-0019: In setListening of AppOpsControllerImpl.java, there is a possible way to hide the microphone privacy indicator when restarting systemUI due to a missing check…
PriorityP422medium5CVSS 3.1
AVLACLPRLUIRSUCNIHAN
EPSS
0.10%
1.2th percentile
In setListening of AppOpsControllerImpl.java, there is a possible way to hide the microphone privacy indicator when restarting systemUI due to a missing check for active recordings. This could lead to local denial of service with no additional execution privileges needed. User interaction is needed for exploitation.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| platform | frameworks_base | >= 12:0 < 12:2024-01-01 | 12:2024-01-01 |
| platform | frameworks_base | >= 12L:0 < 12L:2024-01-01 | 12L:2024-01-01 |
| platform | frameworks_base | >= 13:0 < 13:2024-01-01 | 13:2024-01-01 |
| platform | frameworks_base | >= 14-next:0 < 14-next:2024-01-01 | 14-next:2024-01-01 |
| platform | frameworks_base | >= 14:0 < 14:2024-01-01 | 14:2024-01-01 |
CVSS provenance
nvdv3.15.0MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N
cisa7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-h9xw-259p-x86h: In setListening of AppOpsControllerImpl
ghsa_unreviewed·2024-02-16
CVE-2024-0019 [MEDIUM] CWE-732 GHSA-h9xw-259p-x86h: In setListening of AppOpsControllerImpl
In setListening of AppOpsControllerImpl.java, there is a possible way to hide the microphone privacy indicator when restarting systemUI due to a missing check for active recordings. This could lead to local denial of service with no additional execution privileges needed. User interaction is needed for exploitation.
OSV
CVE-2024-0019: In setListening of AppOpsControllerImpl
osv·2024-01-01
CVE-2024-0019 CVE-2024-0019: In setListening of AppOpsControllerImpl
In setListening of AppOpsControllerImpl.java, there is a possible way to hide the microphone privacy indicator when restarting systemUI due to a missing check for active recordings. This could lead to local denial of service with no additional execution privileges needed. User interaction is needed for exploitation.
CISA
Mitel SIP Phones Argument Injection Vulnerability
cisa·2025-02-12·CVSS 7.2
CVE-2024-41710 [HIGH] CWE-88 Mitel SIP Phones Argument Injection Vulnerability
Vulnerability: Mitel SIP Phones Argument Injection Vulnerability
Affected: Mitel SIP Phones
Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, contain an argument injection vulnerability due to insufficient parameter sanitization during the boot process. Successful exploitation may allow an attacker to execute arbitrary commands within the context of the system.
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Notes: https://www.mitel.com/-/media/mitel/file/pdf/support/security-advisories/security-bulletin_24-0019-001-v2.pdf ; https://nvd.nist.gov/vuln/detail/CVE-2024-41710
Remediation Due Date: 2025-03-05
Android
CVE-2024-0019: Android Security Bulletin 2024-01-01
CVE: CVE-2024-0019
Severity: HIGH
Type: ID
Affected AOSP versions: 12, 12L, 13, 14
References: A-294104969
vendor_android·2024-01-01·CVSS 5.0
CVE-2024-0019 [MEDIUM] CVE-2024-0019: Android Security Bulletin 2024-01-01
CVE: CVE-2024-0019
Severity: HIGH
Type: ID
Affected AOSP versions: 12, 12L, 13, 14
References: A-294104969
Android Security Bulletin 2024-01-01
CVE: CVE-2024-0019
Severity: HIGH
Type: ID
Affected AOSP versions: 12, 12L, 13, 14
References: A-294104969
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://android.googlesource.com/platform/frameworks/base/+/707fc94ec3df4cf6b985e6d06c2588690d1a025ahttps://source.android.com/security/bulletin/2024-01-01https://android.googlesource.com/platform/frameworks/base/+/707fc94ec3df4cf6b985e6d06c2588690d1a025ahttps://source.android.com/security/bulletin/2024-01-01
2024-02-16
Published