PT-2024-15301 · Unknown · Usermanagerservice.Java

Published

2024-05-01

·

Updated

2024-12-17

·

CVE-2024-0024

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions UserManagerService.java (affected versions not specified)
Description The issue is related to improper input validation in multiple methods of UserManagerService.java, which could lead to a failure to persist or enforce user restrictions. This might result in local escalation of privilege with no additional execution privileges needed. User interaction is necessary for exploitation. The vulnerability allows creating users with no restrictions by causing an IOException when creating an intent to create a user with extras that are too long to be serialized, resulting in the restrictions not being written to the file.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Privilege Management

Weakness Enumeration

Related Identifiers

ASB-A-293602317
CVE-2024-0024

Affected Products

Usermanagerservice.Java