PT-2024-24959 · Google · Android+1

Published

2024-06-13

·

Updated

2024-08-08

·

CVE-2024-32906

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions No specific software name or versions are mentioned in the provided descriptions.
Description The issue is related to uninitialized data in the AcvpOnMessage function of avcp.cpp, which could lead to a possible escalation of privilege (EOP) locally, without requiring additional execution privileges or user interaction.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Privilege Management

Use of Uninitialized Resource

Weakness Enumeration

Related Identifiers

CVE-2024-32906

Affected Products

Android
Android Kernel