Local Privilege Escalation in phoneEx Service by Unisoc
CVE-2022-44433

7.8HIGH

What is CVE-2022-44433?

The phoneEx service by Unisoc is impacted by a vulnerability that allows for local privilege escalation due to a missing permission check. An attacker could exploit this oversight to gain elevated privileges without requiring any additional execution permissions, potentially leading to unauthorized access or control over the system resources. Proper permission checks should be implemented to mitigate this risk and secure the integrity of the phoneEx service.

Affected Version(s)

SC9863A/SC9832E/SC7731E/T610/T310/T606/T760/T610/T618/T606/T612/T616/T760/T770/T820/S8000 Android10

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.