CVE Vulnerabilities

CVE-2024-34637

Published: Sep 04, 2024 | Modified: Sep 05, 2024
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Improper access control in WindowManagerService prior to SMR Sep-2024 Release 1 in Android 12, and SMR Jun-2024 Release 1 in Android 13 and Android 14 allows local attackers to bypass restrictions on starting services from the background.

Affected Software

NameVendorStart VersionEnd Version
AndroidSamsung12.0 (including)12.0 (including)
AndroidSamsung12.0-smr_sep-2024-r1 (including)12.0-smr_sep-2024-r1 (including)
AndroidSamsung13.0 (including)13.0 (including)
AndroidSamsung13.0-smr-jun-2024-r1 (including)13.0-smr-jun-2024-r1 (including)
AndroidSamsung14.0 (including)14.0 (including)
AndroidSamsung14.0-smr-jun-2024-r1 (including)14.0-smr-jun-2024-r1 (including)

References