CVE-2024-21633
CVSS 3.1 Score 7.8 of 10 (high)
Details
Summary
CVE-2024-21633 is a vulnerability affecting Apktool, a tool used for reverse engineering Android APK files. In versions 2.9.1 and below, Apktool determines the output path of resource files based on their names, which can be manipulated by attackers to write files to desired locations on the system. This issue is significant as it allows attackers to write or overwrite any file that the user has write access to, and either the user name is known or the current working directory is under the user folder. A patch for this issue is available in commit d348c43b24a9de350ff6e5bd610545a10c1fc712.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- APKTOOL