CVE-2024-0034
published 2024-02-16CVE-2024-0034: In BackgroundLaunchProcessController, there is a possible way to launch arbitrary activity from the background due to BAL Bypass. This could lead to local…
PriorityP343high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.12%
2.0th percentile
In BackgroundLaunchProcessController, there is a possible way to launch arbitrary activity from the background due to BAL Bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| platform | frameworks_base | >= 11:0 < 11:2024-02-01 | 11:2024-02-01 |
| platform | frameworks_base | >= 12:0 < 12:2024-02-01 | 12:2024-02-01 |
| platform | frameworks_base | >= 12L:0 < 12L:2024-02-01 | 12L:2024-02-01 |
| platform | frameworks_base | >= 13:0 < 13:2024-02-01 | 13:2024-02-01 |
| platform | frameworks_base | >= 14-next:0 < 14-next:2024-02-01 | 14-next:2024-02-01 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4974-7pgr-4grv: In BackgroundLaunchProcessController, there is a possible way to launch arbitrary activity from the background due to BAL Bypass
ghsa_unreviewed·2024-02-16
CVE-2024-0034 [HIGH] CWE-276 GHSA-4974-7pgr-4grv: In BackgroundLaunchProcessController, there is a possible way to launch arbitrary activity from the background due to BAL Bypass
In BackgroundLaunchProcessController, there is a possible way to launch arbitrary activity from the background due to BAL Bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
OSV
CVE-2024-0034: In BackgroundLaunchProcessController, there is a possible way to launch arbitrary activity from the background due to BAL Bypass
osv·2024-02-01
CVE-2024-0034 CVE-2024-0034: In BackgroundLaunchProcessController, there is a possible way to launch arbitrary activity from the background due to BAL Bypass
In BackgroundLaunchProcessController, there is a possible way to launch arbitrary activity from the background due to BAL Bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Android
CVE-2024-0034: Android Security Bulletin 2024-02-01
CVE: CVE-2024-0034
Severity: HIGH
Type: EoP
Affected AOSP versions: 11, 12, 12L, 13
References: A-298094386
vendor_android·2024-02-01·CVSS 7.8
CVE-2024-0034 [HIGH] CVE-2024-0034: Android Security Bulletin 2024-02-01
CVE: CVE-2024-0034
Severity: HIGH
Type: EoP
Affected AOSP versions: 11, 12, 12L, 13
References: A-298094386
Android Security Bulletin 2024-02-01
CVE: CVE-2024-0034
Severity: HIGH
Type: EoP
Affected AOSP versions: 11, 12, 12L, 13
References: A-298094386
Suricata
ET EXPLOIT Possible Elasticsearch CVE-2015-1427 Exploit Campaign SSL Certificate
suricata·2015-06-26·CVSS 9.8
CVE-2015-1427 [CRITICAL] ET EXPLOIT Possible Elasticsearch CVE-2015-1427 Exploit Campaign SSL Certificate
ET EXPLOIT Possible Elasticsearch CVE-2015-1427 Exploit Campaign SSL Certificate
Rule: alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"ET EXPLOIT Possible Elasticsearch CVE-2015-1427 Exploit Campaign SSL Certificate"; flow:established,to_client; tls.cert_subject; content:"ST="; distance:0; content:"hacked"; content:"|01 09 01|"; distance:0; content:"[email protected]"; reference:url,blog.malwaremustdie.org/2015/06/mmd-0034-2015-new-elf.html; classtype:trojan-activity; sid:2021351; rev:4; metadata:attack_target Client_Endpoint, created_at 2015_06_26, cve CVE_2015_1427, deployment Perimeter, confidence Medium, signature_severity Major, tag SSL_Malicious_Cert, tag CISA_KEV, updated_at 2024_04_12;)
No public exploits indexed.
No writeups or analysis indexed.
https://android.googlesource.com/platform/frameworks/base/+/653f7b0d234693309dc86161af01831b64033fe6https://source.android.com/security/bulletin/2024-02-01https://android.googlesource.com/platform/frameworks/base/+/653f7b0d234693309dc86161af01831b64033fe6https://source.android.com/security/bulletin/2024-02-01
2024-02-16
Published