CVE-2024-0032
published 2024-02-16CVE-2024-0032: In multiple locations, there is a possible way to request access to directories that should be hidden due to improper input validation. This could lead to…
PriorityP429medium6.5CVSS 3.1
AVLACLPRHUIRSUCHIHAH
EPSS
0.45%
36.9th percentile
In multiple locations, there is a possible way to request access to directories that should be hidden due to improper input validation. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| platform | frameworks_base | >= 12:0 < 12:2025-03-01 | 12:2025-03-01 |
| platform | frameworks_base | >= 12L:0 < 12L:2025-03-01 | 12L:2025-03-01 |
| platform | frameworks_base | >= 13:0 < 13:2025-03-01 | 13:2025-03-01 |
| platform | frameworks_base | >= 14:0 < 14:2025-03-01 | 14:2025-03-01 |
| platform | frameworks_base | >= 15-next:0 < 15-next:2025-03-01 | 15-next:2025-03-01 |
| platform | packages_providers_downloadprovider | >= 12:0 < 12:2025-03-01 | 12:2025-03-01 |
| platform | packages_providers_downloadprovider | >= 12L:0 < 12L:2025-03-01 | 12L:2025-03-01 |
| platform | packages_providers_downloadprovider | >= 13:0 < 13:2025-03-01 | 13:2025-03-01 |
| platform | packages_providers_downloadprovider | >= 14:0 < 14:2025-03-01 | 14:2025-03-01 |
| platform | packages_providers_downloadprovider | >= 15-next:0 < 15-next:2025-03-01 | 15-next:2025-03-01 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Android
CVE-2024-0032: Android Security Bulletin 2025-03-01
CVE: CVE-2024-0032
Severity: HIGH
Type: EoP
Affected AOSP versions: 12, 12L, 13, 14
References: A-283962634
[2]
vendor_android·2025-03-01·CVSS 6.5
CVE-2024-0032 [MEDIUM] CVE-2024-0032: Android Security Bulletin 2025-03-01
CVE: CVE-2024-0032
Severity: HIGH
Type: EoP
Affected AOSP versions: 12, 12L, 13, 14
References: A-283962634
[2]
Android Security Bulletin 2025-03-01
CVE: CVE-2024-0032
Severity: HIGH
Type: EoP
Affected AOSP versions: 12, 12L, 13, 14
References: A-283962634
[2]
OSV
CVE-2024-0032: In multiple locations, there is a possible way to request access to directories that should be hidden due to improper input validation
osv·2025-03-01
CVE-2024-0032 CVE-2024-0032: In multiple locations, there is a possible way to request access to directories that should be hidden due to improper input validation
In multiple locations, there is a possible way to request access to directories that should be hidden due to improper input validation. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.
GHSA
GHSA-3459-9h5c-8q2x: In queryChildDocuments of FileSystemProvider
ghsa_unreviewed·2024-02-16
CVE-2024-0032 [MEDIUM] CWE-284 GHSA-3459-9h5c-8q2x: In queryChildDocuments of FileSystemProvider
In queryChildDocuments of FileSystemProvider.java, there is a possible way to request access to directories that should be hidden due to improper input validation. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://android.googlesource.com/platform/frameworks/base/+/a6321142ea43053ea8d0db516eede4c35c5dab18https://android.googlesource.com/platform/packages/providers/DownloadProvider/+/b2cc552f8e1ed982e6662f64baa2cdbf1acaf777https://source.android.com/security/bulletin/2025-03-01https://android.googlesource.com/platform/frameworks/base/+/4af5db76f25348849252e0b8a08f4a517ef842b7https://android.googlesource.com/platform/packages/providers/DownloadProvider/+/5acd646e0cf63e2c9c0862da7e03531ef0074394https://source.android.com/security/bulletin/2024-02-01
2024-02-16
Published