CVE-2024-0029
published 2024-02-16CVE-2024-0029: In multiple files, there is a possible way to capture the device screen when disallowed by device policy due to a logic error in the code. This could lead to…
PriorityP342high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.14%
3.8th percentile
In multiple files, there is a possible way to capture the device screen when disallowed by device policy due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| platform | frameworks_base | >= 13:0 < 13:2024-02-01 | 13:2024-02-01 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
cisa9.1CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Mitel MiCollab Path Traversal Vulnerability
cisa·2025-01-07·CVSS 9.1
CVE-2024-41713 [CRITICAL] CWE-22 Mitel MiCollab Path Traversal Vulnerability
Vulnerability: Mitel MiCollab Path Traversal Vulnerability
Affected: Mitel MiCollab
Mitel MiCollab contains a path traversal vulnerability that could allow an attacker to gain unauthorized and unauthenticated access. This vulnerability can be chained with CVE-2024-55550, which allows an unauthenticated, remote attacker to read arbitrary files on the server.
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Notes: https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-misa-2024-0029 ; https://nvd.nist.gov/vuln/detail/CVE-2024-41713
Remediation Due Date: 2025-01-28
CISA
Mitel MiCollab Path Traversal Vulnerability
cisa·2025-01-07·CVSS 9.1
CVE-2024-55550 [CRITICAL] CWE-22 Mitel MiCollab Path Traversal Vulnerability
Vulnerability: Mitel MiCollab Path Traversal Vulnerability
Affected: Mitel MiCollab
Mitel MiCollab contains a path traversal vulnerability that could allow an authenticated attacker with administrative privileges to read local files within the system due to insufficient input sanitization. This vulnerability can be chained with CVE-2024-41713, which allows an unauthenticated, remote attacker to read arbitrary files on the server.
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Notes: https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-misa-2024-0029 ; https://nvd.nist.gov/vuln/detail/CVE-2024-55550
Remediation Due Date: 2025-01-28
Android
CVE-2024-0029: Android Security Bulletin 2024-02-01
CVE: CVE-2024-0029
Severity: HIGH
Type: EoP
Affected AOSP versions: 13
References: A-305664128
vendor_android·2024-02-01·CVSS 7.8
CVE-2024-0029 [HIGH] CVE-2024-0029: Android Security Bulletin 2024-02-01
CVE: CVE-2024-0029
Severity: HIGH
Type: EoP
Affected AOSP versions: 13
References: A-305664128
Android Security Bulletin 2024-02-01
CVE: CVE-2024-0029
Severity: HIGH
Type: EoP
Affected AOSP versions: 13
References: A-305664128
GHSA
GHSA-g4m7-c39m-vp4f: In multiple files, there is a possible way to capture the device screen when disallowed by device policy due to a logic error in the code
ghsa_unreviewed·2024-02-16
CVE-2024-0029 [HIGH] CWE-693 GHSA-g4m7-c39m-vp4f: In multiple files, there is a possible way to capture the device screen when disallowed by device policy due to a logic error in the code
In multiple files, there is a possible way to capture the device screen when disallowed by device policy due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
OSV
CVE-2024-0029: In multiple files, there is a possible way to capture the device screen when disallowed by device policy due to a logic error in the code
osv·2024-02-01
CVE-2024-0029 CVE-2024-0029: In multiple files, there is a possible way to capture the device screen when disallowed by device policy due to a logic error in the code
In multiple files, there is a possible way to capture the device screen when disallowed by device policy due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://android.googlesource.com/platform/frameworks/base/+/9b10fd9718f4e6f6843adbfc14e46a93aab93aadhttps://source.android.com/security/bulletin/2024-02-01https://android.googlesource.com/platform/frameworks/base/+/9b10fd9718f4e6f6843adbfc14e46a93aab93aadhttps://source.android.com/security/bulletin/2024-02-01
2024-02-16
Published