PT-2022-14250 · Google · Android

Published

2022-03-30

·

Updated

2023-08-08

·

CVE-2022-20002

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Android versions Android-12L
Description The issue is related to a missing permission check in incfs, allowing for the mounting of arbitrary paths. This could lead to local escalation of privilege, with System execution privileges required for exploitation. No user interaction is needed for exploitation.
Recommendations For Android version Android-12L, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2022-20002

Affected Products

Android