CVE-2024-0024Improper Privilege Management in Frameworks Base

Severity
7.8HIGHNVD
EPSS
0.0%
top 92.93%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 7
Latest updateMay 17

Description

In multiple methods of UserManagerService.java, there is a possible failure to persist or enforce user restrictions due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages4 packages

Androidplatform/frameworks_base14-next:014-next:2024-05-01+4
CVEListV5google/android4 versions+3
NVDgoogle/android4 versions+3

Patches

🔴Vulnerability Details

2
GHSA
GHSA-wmq9-769v-mqmc: In multiple methods of UserManagerService2024-05-07
OSV
CVE-2024-0024: In multiple methods of UserManagerService2024-05-01

📋Vendor Advisories

1
Android
CVE-2024-0024: Android Security Bulletin 2024-05-01 CVE: CVE-2024-0024 Severity: HIGH Type: EoP Affected AOSP versions: 12, 12L, 13, 14 References: A-2936023172024-05-01

💬Community

1
Bugzilla
CVE-2024-35828 kernel: wifi: libertas: fix some memleaks in lbs_allocate_cmd_buffer()2024-05-17