2024-09-11 18:03:18 +00:00

29 lines
1.6 KiB
JSON

{
"id": "CVE-2024-40659",
"sourceIdentifier": "security@android.com",
"published": "2024-09-11T00:15:11.473",
"lastModified": "2024-09-11T16:26:11.920",
"vulnStatus": "Awaiting Analysis",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "In getRegistration of RemoteProvisioningService.java, there is a possible way to permanently disable the AndroidKeyStore key generation feature by updating the attestation keys of all installed apps due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation."
},
{
"lang": "es",
"value": "En getRegistration de RemoteProvisioningService.java, existe una forma posible de deshabilitar permanentemente la funci\u00f3n de generaci\u00f3n de claves de AndroidKeyStore mediante la actualizaci\u00f3n de las claves de certificaci\u00f3n de todas las aplicaciones instaladas debido a una validaci\u00f3n de entrada incorrecta. Esto podr\u00eda provocar una denegaci\u00f3n de servicio local sin necesidad de privilegios de ejecuci\u00f3n adicionales. No se necesita la interacci\u00f3n del usuario para la explotaci\u00f3n."
}
],
"metrics": {},
"references": [
{
"url": "https://android.googlesource.com/platform/packages/modules/RemoteKeyProvisioning/+/c65dce4c6d8d54e47dce79a56e29e2223a2354e6",
"source": "security@android.com"
},
{
"url": "https://source.android.com/security/bulletin/2024-09-01",
"source": "security@android.com"
}
]
}