PT-2023-7530 · Google · Android

Tchebb

·

Publicado

2023-12-01

·

Atualizado

2024-02-13

·

CVE-2023-45779

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Android versions prior to 2023-12-05 security patch
Description The issue is related to the APEX module framework of AOSP, where improperly used crypto could lead to a malicious update of platform components. This could result in local escalation of privilege with no additional execution privileges needed. User interaction is not required for exploitation. Several Android OEMs, including ASUS, Fairphone, Lenovo, Microsoft, Nokia, Nothing, and Vivo, were affected as they were signing some of their APEX modules with publicly available test keys.
Recommendations For Android versions prior to 2023-12-05 security patch, update to a version that includes the December 2023 security update to resolve the issue. As a temporary workaround, consider restricting access to the APEX module framework until a patch is available.

Exploit

Correção

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-08584
CVE-2023-45779

Produtos afetados

Android