cve/2024/CVE-2024-0014.md
2024-05-25 21:48:12 +02:00

760 B

CVE-2024-0014

Description

In startInstall of UpdateFetcher.java, there is a possible way to trigger a malicious config update due to a logic error. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

POC

Reference

No PoCs from references.

Github