CVE-2022-38064: windowmanager in window subsystem has a permission bypass vulnerability. Local attackers can bypass permission control and get sensitive information.
Published Sep 9, 2022
·Updated
OpenHarmony-v3.1.2 and prior versions have a permission bypass vulnerability. Local attackers can bypass permission control and get sensitive information.
Affected Software
1 affected component
OpenHarmony OpenHarmony>=3.1<=3.1.2
Event History
Sep 9, 2022
CVE Published
via MITRE·02:39 PM
Data Sourced
via MITRE·02:39 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2022-38064?
CVE-2022-38064 is a permission bypass vulnerability in OpenHarmony-v3.1.2 and prior versions.
2
How does CVE-2022-38064 work?
CVE-2022-38064 allows local attackers to bypass permission control and access sensitive information.
3
What is the severity of CVE-2022-38064?
The severity of CVE-2022-38064 is medium with a score of 5.5.
4
How can I fix CVE-2022-38064?
To fix CVE-2022-38064, update OpenHarmony to version 3.1.2 or later.
5
Where can I find more information about CVE-2022-38064?
More information about CVE-2022-38064 can be found at the following reference: [CVE-2022-38064](https://gitee.com/openharmony/security/blob/master/en/security-disclosure/2022/2022-09.md).