PT-2022-14376 · Google · Android

Published

2022-06-01

·

Updated

2023-08-08

·

CVE-2022-20138

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Android versions Android-10 through Android-12L
Description A missing permission check in the ACTION MANAGED PROFILE PROVISIONED intent of DevicePolicyManagerService.java allows an unprivileged app to send the intent, potentially leading to local escalation of privilege. No additional execution privileges are needed, and user interaction is not required for exploitation.
Recommendations For Android versions Android-10 through Android-12L, at the moment, there is no information about a newer version that contains a fix for this issue.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

ASB-A-210469972
CVE-2022-20138

Affected Products

Android