PT-2019-16307 · Google · Android

Publicado

2019-12-06

·

Atualizado

2019-12-09

·

CVE-2019-2225

CVSS v3.1

8.8

Alta

VetorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Android versions 8.0 through 10
Description A potential issue exists when pairing with a Bluetooth device, allowing a malicious device to pair without user confirmation. This paired device may interact with the phone, potentially leading to remote escalation of privilege with no additional execution privileges needed. User interaction is not required for exploitation.
Recommendations For Android versions 8.0 through 10, consider disabling Bluetooth pairing until a fix is available to prevent potential exploitation. Restrict access to sensitive phone features to minimize the risk of privilege escalation.

Correção

Improper Privilege Management

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-2225

Produtos afetados

Android