CVE Vulnerabilities

CVE-2024-34637

Published: Sep 04, 2024 | Modified: Sep 05, 2024
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Improper access control in WindowManagerService prior to SMR Sep-2024 Release 1 in Android 12, and SMR Jun-2024 Release 1 in Android 13 and Android 14 allows local attackers to bypass restrictions on starting services from the background.

Affected Software

Name Vendor Start Version End Version
Android Samsung 12.0 (including) 12.0 (including)
Android Samsung 12.0-smr_sep-2024-r1 (including) 12.0-smr_sep-2024-r1 (including)
Android Samsung 13.0 (including) 13.0 (including)
Android Samsung 13.0-smr-jun-2024-r1 (including) 13.0-smr-jun-2024-r1 (including)
Android Samsung 14.0 (including) 14.0 (including)
Android Samsung 14.0-smr-jun-2024-r1 (including) 14.0-smr-jun-2024-r1 (including)

References