CVE-2024-44095 is a local escalation of privilege vulnerability affecting Google Android devices, stemming from a logic error in the ppmp_protect_mfcfw_buf function. This flaw carries a CVSS score of 7.8 (High), indicating a significant risk due to its low attack complexity, requiring no user interaction or additional execution privileges, and potentially leading to full compromise of confidentiality, integrity, and availability. While not currently listed in CISA's KEV catalog or having public exploit code, it has garnered some community discussion and media coverage, suggesting awareness within the security community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:google:android:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.