PT-2023-22384 · Unknown · Lock Master

Published

2023-05-30

·

Updated

2025-01-14

·

CVE-2023-29733

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions The Lock Master app version 2.2.4
Description The issue allows unauthorized apps to modify the values in the SharedPreference files of the Lock Master app. These files hold data that affects many app functions. Malicious modifications by unauthorized apps can cause security issues, such as functionality manipulation, resulting in a severe escalation of privilege attack.
Recommendations For version 2.2.4, consider restricting access to the SharedPreference files until a patch is available. As a temporary workaround, review and monitor the app's functionality regularly to detect any potential malicious modifications. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Incorrect Default Permissions

Weakness Enumeration

Related Identifiers

CVE-2023-29733

Affected Products

Lock Master