ASB-A-210469972
Dashboard / Vulnerabilities / ASB-A-210469972
Summary:
Details: In ACTION_MANAGED_PROFILE_PROVISIONED of DevicePolicyManagerService.java, there is a possible way for unprivileged app to send MANAGED_PROFILE_PROVISIONED intent due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
References: https://source.android.com/security/bulletin/2022-06-01, https://android.googlesource.com/platform/frameworks/base/+/b519b549fdb029dcdb6a51de944897e04e114e5f, https://android.googlesource.com/platform/packages/apps/ManagedProvisioning/+/1a7ef6ddd4c267323cd017c752d4da5392de0390
Affected packages
Package
Name: platform/frameworks/base
Purl:
Affected ranges
Type: ECOSYSTEM
Events:
