PT-2019-16139 · Google · Android

Publicado

2019-11-13

·

Atualizado

2020-08-24

·

CVE-2019-2036

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Android versions 8.0 through 10
Description The issue is related to a possible permission bypass in the okToConnect function of HidHostService.java. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not required for exploitation.
Recommendations For Android versions 8.0 through 10, apply the fix for the incorrect state check in the okToConnect function of HidHostService.java to prevent permission bypass and potential remote escalation of privilege.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2019-2036

Produtos afetados

Android