In access_secure_service_from_temp_bond of btm_sec.cc,...
Critical severity
Unreviewed
Published
Mar 11, 2024
to the GitHub Advisory Database
•
Updated Aug 16, 2024
Description
Published by the National Vulnerability Database
Mar 11, 2024
Published to the GitHub Advisory Database
Mar 11, 2024
Last updated
Aug 16, 2024
In access_secure_service_from_temp_bond of btm_sec.cc, there is a possible way to achieve keystroke injection due to improper input validation. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
References