PT-2024-12852 · Google · Android

Published

2023-11-01

·

Updated

2024-12-13

·

CVE-2023-40114

CVSS v3.1

8.4

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Android versions prior to the latest patch
Description The issue is related to a possible out of bounds write due to a use after free in multiple functions of MtpFfsHandle.cpp. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is required for exploitation.
Recommendations For Android versions prior to the latest patch, apply the latest security patch to resolve the issue. As a temporary workaround, consider restricting access to the MtpFfsHandle.cpp functions until a patch is available.

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ASB-A-243381410
CVE-2023-40114

Affected Products

Android