CVE-2023-21121

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Jun 15, 2023
Updated: Dec 18, 2024
CWE ID 276
CWE ID 20

Summary

CVE-2023-21121 is a vulnerability affecting Android versions 11 and 12. In the AppManagementFragment.java file, there is a flaw in the onResume function that allows an attacker to prevent the forgetting of a previously connected VPN. This improper input validation can result in local privilege escalation without requiring any additional execution privileges. Notably, user interaction is not necessary for exploitation. (Android ID: A-205460459)

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share