CVE-2023-44128

Published Sep 27, 2023

Last updated a year ago

Overview

Description
he vulnerability is to delete arbitrary files in LGInstallService ("com.lge.lginstallservies") app. The app contains the exported "com.lge.lginstallservies.InstallService" service that exposes an AIDL interface. All its "installPackage*" methods are finally calling the "installPackageVerify()" method that performs signature validation after the delete file method. An attacker can control conditions so this security check is never performed and an attacker-controlled file is deleted.
Source
product.security@lge.com
NVD status
Analyzed

Risk scores

CVSS 3.1

Type
Primary
Base score
3.6
Impact score
2.5
Exploitability score
1
Vector string
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L
Severity
LOW

Weaknesses

nvd@nist.gov
CWE-367
product.security@lge.com
CWE-367

Social media

Hype score
Not currently trending

Configurations