CVE Vulnerabilities

CVE-2024-0048

Published: Mar 11, 2024 | Modified: Dec 16, 2024
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

In Session of AccountManagerService.java, there is a possible method to retain foreground service privileges due to incorrect handling of null responses. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Affected Software

Name Vendor Start Version End Version
Android Google 12.0 (including) 12.0 (including)
Android Google 12.1 (including) 12.1 (including)
Android Google 13.0 (including) 13.0 (including)
Android Google 14.0 (including) 14.0 (including)
Android-framework-23 Ubuntu devel *
Android-framework-23 Ubuntu esm-apps/bionic *
Android-framework-23 Ubuntu esm-apps/focal *
Android-framework-23 Ubuntu esm-apps/jammy *
Android-framework-23 Ubuntu esm-apps/noble *
Android-framework-23 Ubuntu focal *
Android-framework-23 Ubuntu jammy *
Android-framework-23 Ubuntu mantic *
Android-framework-23 Ubuntu noble *
Android-framework-23 Ubuntu oracular *
Android-platform-frameworks-base Ubuntu devel *
Android-platform-frameworks-base Ubuntu esm-apps/bionic *
Android-platform-frameworks-base Ubuntu esm-apps/focal *
Android-platform-frameworks-base Ubuntu esm-apps/jammy *
Android-platform-frameworks-base Ubuntu esm-apps/noble *
Android-platform-frameworks-base Ubuntu esm-apps/xenial *
Android-platform-frameworks-base Ubuntu focal *
Android-platform-frameworks-base Ubuntu jammy *
Android-platform-frameworks-base Ubuntu mantic *
Android-platform-frameworks-base Ubuntu noble *
Android-platform-frameworks-base Ubuntu oracular *

References