CVE-2024-40662
published 2024-09-11CVE-2024-40662: In scheme of Uri.java, there is a possible way to craft a malformed Uri object due to improper input validation. This could lead to local escalation of…
PriorityP342high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.10%
0.9th percentile
In scheme of Uri.java, there is a possible way to craft a malformed Uri object due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vj44-f7fj-3gf2: In scheme of Uri
ghsa_unreviewed·2024-09-11
CVE-2024-40662 [HIGH] CWE-269 GHSA-vj44-f7fj-3gf2: In scheme of Uri
In scheme of Uri.java, there is a possible way to craft a malformed Uri object due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
OSV
CVE-2024-40662: In scheme of Uri
osv·2024-09-11·CVSS 7.8
CVE-2024-40662 [HIGH] CVE-2024-40662: In scheme of Uri
In scheme of Uri.java, there is a possible way to craft a malformed Uri object due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Android
CVE-2024-40662: Android Security Bulletin 2024-09-01
CVE: CVE-2024-40662
Severity: HIGH
Type: EoP
Affected AOSP versions: 12, 12L, 13, 14
References: A-261721900
vendor_android·2024-09-01·CVSS 7.8
CVE-2024-40662 [HIGH] CVE-2024-40662: Android Security Bulletin 2024-09-01
CVE: CVE-2024-40662
Severity: HIGH
Type: EoP
Affected AOSP versions: 12, 12L, 13, 14
References: A-261721900
Android Security Bulletin 2024-09-01
CVE: CVE-2024-40662
Severity: HIGH
Type: EoP
Affected AOSP versions: 12, 12L, 13, 14
References: A-261721900
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-09-11
Published