CVE-2024-40659 - AndroidKeyStore Local DoS Vulnerability in RemoteProvisioningService

2 months ago 31
ARTICLE AD BOX
CVE ID : CVE-2024-40659
Published : Sept. 11, 2024, 12:15 a.m. | 24 minutes ago
Description : In getRegistration of RemoteProvisioningService.java, there is a possible way to permanently disable the AndroidKeyStore key generation feature by updating the attestation keys of all installed apps due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Read Entire Article