peter bassill · operator
$ cve CVE-2024-43093 JSON

CVE-2024-43093 KEV

7.3
HIGH · CVSS 3.1 · EPSS 0.7% (pctl 52)

Patch first

On CISA KEV — known exploited in the wild, due 2024-11-28.

Description

In shouldHideDocument of ExternalStorageProvider.java, there is a possible bypass of a file path filter designed to prevent access to sensitive directories due to incorrect unicode normalization. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

Scoring

CVSS7.3 (HIGH, v3.1)
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
EPSS0.72% — more likely to be exploited than 52% of all CVEs
WeaknessCWE-176
On CISA KEVyes — remediate by 2024-11-28
Public exploitnone known
Published2024-11-13
Last modified2026-06-17

CISA KEV

NameAndroid Framework Privilege Escalation Vulnerability
Added2024-11-07
Due2024-11-28
Vendor / productAndroid / Framework
Ransomware usenone reported

Affected (1)

VendorProduct
googleandroid

References

→ the Explorer  ·  watch your stack  ·  NVD