CVE Vulnerabilities

CVE-2023-20917

Published: Mar 24, 2023 | Modified: Mar 29, 2023
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

In onTargetSelected of ResolverActivity.java, there is a possible way to share a wrong file due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-242605257

Affected Software

Name Vendor Start Version End Version
Android Google 11.0 (including) 11.0 (including)
Android Google 12.0 (including) 12.0 (including)
Android Google 12.1 (including) 12.1 (including)
Android Google 13.0 (including) 13.0 (including)
Android-framework-23 Ubuntu bionic *
Android-framework-23 Ubuntu kinetic *
Android-framework-23 Ubuntu lunar *
Android-framework-23 Ubuntu mantic *
Android-framework-23 Ubuntu trusty *
Android-framework-23 Ubuntu xenial *
Android-platform-frameworks-base Ubuntu bionic *
Android-platform-frameworks-base Ubuntu kinetic *
Android-platform-frameworks-base Ubuntu lunar *
Android-platform-frameworks-base Ubuntu mantic *
Android-platform-frameworks-base Ubuntu trusty *
Android-platform-frameworks-base Ubuntu xenial *

References