ASB-A-210469972 PUBLISHED

In ACTION_MANAGED_PROFILE_PROVISIONED of DevicePolicyManagerService.java, there is a possible way for unprivileged app to send MANAGED_PROFILE_PROVISIONED intent due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Affected Products

VendorProductVersions
platformframeworks/base*, 10:0, 10
platformpackages/apps/ManagedProvisioning10:0, 10, 11:0

Timeline

References

Open in Interactive Console →