← voltar
CVE-2024-23717

CVE-2024-23717

CVSS 9.1 CRITICALEPSS 0.4%CWE-20
In access_secure_service_from_temp_bond of btm_sec.cc, there is a possible way to achieve keystroke injection due to improper input validation. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Produtos afetados
Google · Android

Quer saber se a sua infraestrutura está exposta a isto?

Falar com a TrueHacking →