CVE-2024-34742

In shouldWrite of OwnersData.java, there is a possible edge case that prevents MDM policies from being persisted due to a logic error in the code. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
Configurations

Configuration 1 (hide)

cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:*

History

25 Nov 2024, 18:15

Type Values Removed Values Added
CWE CWE-843

21 Nov 2024, 22:58

Type Values Removed Values Added
CWE NVD-CWE-noinfo
CPE cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:*
References () https://android.googlesource.com/platform/frameworks/base/+/688e5c3012eb0a4ea88361588cf5026c10e4a42c - () https://android.googlesource.com/platform/frameworks/base/+/688e5c3012eb0a4ea88361588cf5026c10e4a42c - Patch
References () https://source.android.com/security/bulletin/2024-08-01 - () https://source.android.com/security/bulletin/2024-08-01 - Patch, Vendor Advisory
First Time Google
Google android
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5

19 Aug 2024, 13:00

Type Values Removed Values Added
Summary
  • (es) En shouldWrite de OwnersData.java, existe un posible caso límite que impide que las políticas de MDM persistan debido a un error lógico en el código. Esto podría provocar una denegación de servicio local sin necesidad de privilegios de ejecución adicionales. La interacción del usuario no es necesaria para la explotación.

15 Aug 2024, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-08-15 22:15

Updated : 2024-11-25 18:15


NVD link : CVE-2024-34742

Mitre link : CVE-2024-34742

CVE.ORG link : CVE-2024-34742


JSON object : View

Products Affected

google

  • android
CWE
NVD-CWE-noinfo CWE-843

Access of Resource Using Incompatible Type ('Type Confusion')