CVE-2022-44433: High severity android vulnerability
Published May 9, 2023
·Updated
In phoneEx service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges.
Affected Software
28 affected components
All of the following
Google Android=10.0
Any of the following
UNISOC S8000
UNISOC Sc7731e
UNISOC Sc9832e
UNISOC Sc9863a
UNISOC T310
UNISOC T606
UNISOC T610
UNISOC T612
UNISOC T616
UNISOC T618
UNISOC T760
UNISOC T770
UNISOC T820
Google Android=10.0
UNISOC S8000
UNISOC Sc7731e
UNISOC Sc9832e
UNISOC Sc9863a
UNISOC T310
UNISOC T606
UNISOC T610
UNISOC T612
UNISOC T616
UNISOC T618
UNISOC T760
UNISOC T770
UNISOC T820
Event History
May 9, 2023
CVE Published
via MITRE·01:21 AM
Data Sourced
via MITRE·01:21 AM
Description
Data Sourced
02:15 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-44433?
CVE-2022-44433 is considered to have a moderate severity due to the potential for local escalation of privilege.
2
How do I fix CVE-2022-44433?
To mitigate CVE-2022-44433, ensure that proper permission checks are implemented in the phoneEx service.
3
What systems are affected by CVE-2022-44433?
CVE-2022-44433 affects devices running Google Android 10.0.
4
Can CVE-2022-44433 be exploited remotely?
CVE-2022-44433 cannot be exploited remotely as it requires local access to the affected device.
5
Who is impacted by CVE-2022-44433?
Users of devices with Google Android 10.0 and the specific phoneEx service are at risk from CVE-2022-44433.