CVE-2024-43769
published 2025-01-03CVE-2024-43769: In isPackageDeviceAdmin of PackageManagerService.java, there is a possible edge case which could prevent the uninstallation of CloudDpc due to a logic error in…
PriorityP341high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.08%
0.3th percentile
In isPackageDeviceAdmin of PackageManagerService.java, there is a possible edge case which could prevent the uninstallation of CloudDpc due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| platform | frameworks_base | >= 13:0 < 13:2024-12-01 | 13:2024-12-01 |
| platform | frameworks_base | >= 14:0 < 14:2024-12-01 | 14:2024-12-01 |
| platform | frameworks_base | >= 15-next:0 < 15-next:2024-12-01 | 15-next:2024-12-01 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Liferay Portal vulnerable to Stored XSS in Components portlet
ghsa·2025-08-23
CVE-2025-43769 [MEDIUM] CWE-79 Liferay Portal vulnerable to Stored XSS in Components portlet
Liferay Portal vulnerable to Stored XSS in Components portlet
Stored cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q3.1 through 2024.Q3.8, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12 and 7.4 GA through update 92 allows remote attackers to execute arbitrary web script or HTML via components tab.
GHSA
GHSA-2f82-fhcf-rx3f: In isPackageDeviceAdmin of PackageManagerService
ghsa_unreviewed·2025-01-03
CVE-2024-43769 [HIGH] CWE-276 GHSA-2f82-fhcf-rx3f: In isPackageDeviceAdmin of PackageManagerService
In isPackageDeviceAdmin of PackageManagerService.java, there is a possible edge case which could prevent the uninstallation of CloudDpc due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
OSV
CVE-2024-43769: In isPackageDeviceAdmin of PackageManagerService
osv·2024-12-01
CVE-2024-43769 CVE-2024-43769: In isPackageDeviceAdmin of PackageManagerService
In isPackageDeviceAdmin of PackageManagerService.java, there is a possible edge case which could prevent the uninstallation of CloudDpc due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Android
CVE-2024-43769: Android Security Bulletin 2024-12-01
CVE: CVE-2024-43769
Severity: HIGH
Type: EoP
Affected AOSP versions: 13, 14, 15
References: A-360807442
vendor_android·2024-12-01·CVSS 7.8
CVE-2024-43769 [HIGH] CVE-2024-43769: Android Security Bulletin 2024-12-01
CVE: CVE-2024-43769
Severity: HIGH
Type: EoP
Affected AOSP versions: 13, 14, 15
References: A-360807442
Android Security Bulletin 2024-12-01
CVE: CVE-2024-43769
Severity: HIGH
Type: EoP
Affected AOSP versions: 13, 14, 15
References: A-360807442
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-01-03
Published