PT-2022-20264 · Unknown · Personamanagerservice
Published
2022-06-07
·
Updated
2022-06-11
·
CVE-2022-30727
CVSS v3.1
6.2
Medium
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
PersonaManagerService versions prior to SMR Jun-2022 Release 1
Description
The issue is related to improper handling of insufficient permissions in the
addAppPackageNameToAllowList function within the PersonaManagerService. This allows local attackers to modify certain setting values in the workspace.Recommendations
For versions prior to SMR Jun-2022 Release 1, update to the SMR Jun-2022 Release 1 or later to resolve the issue.
Fix
Improper Handling of Exceptional Conditions
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Personamanagerservice