CVE-2024-21633

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Jan 3, 2024
Updated: Jan 10, 2024
CWE ID 22

Summary

CVE-2024-21633 is a vulnerability affecting Apktool, a tool used for reverse engineering Android APK files. In versions 2.9.1 and below, Apktool determines the output path of resource files based on their names, which can be manipulated by attackers to write files to desired locations on the system. This issue is significant as it allows attackers to write or overwrite any file that the user has write access to, and either the user name is known or the current working directory is under the user folder. A patch for this issue is available in commit d348c43b24a9de350ff6e5bd610545a10c1fc712.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share