5.5
CVE-2025-48633
- EPSS 0.26%
- Veröffentlicht 08.12.2025 17:16:19
- Zuletzt bearbeitet 07.10.2026 20:10:01
- Erkennungen
In hasAccountsOnAnyUser of DevicePolicyManagerService.java, there is a possible way to add a Device Owner after provisioning due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
02.12.2025: CISA Known Exploited Vulnerabilities (KEV) Catalog
Android Framework Information Disclosure Vulnerability
SchwachstelleAndroid Framework contains an unspecified vulnerability that allows for information disclosure.
BeschreibungApply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Erforderliche Maßnahmen| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.26% | 0.171 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5.5 | 1.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
| CISA-ADP | 5.5 | 1.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
https://source.android.com/security/bulletin/2025-12-01
https://android.googlesource.com/platform/frameworks/base/+/d00bcda9f42dcf272d329e9bf9298f32af732f93
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-48633