PT-2021-13011 · Google · Android

Published

2021-02-01

·

Updated

2021-02-12

·

CVE-2021-0330

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Android versions Android-9 through Android-11
Description: The issue is related to a possible use-after-free due to improper locking in the add user ce and remove user ce functions of storaged.cpp. This could lead to local escalation of privilege in storaged with no additional execution privileges needed. User interaction is not needed for exploitation.
Recommendations: For Android versions Android-9 through Android-11, consider applying the necessary patches or fixes to resolve the improper locking issue in storaged.cpp to prevent potential local escalation of privilege. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ASB-A-170732441
CVE-2021-0330

Affected Products

Android