CVE-2021-25356

HIGH

Managed Provisioning <SMR APR-2021 Release 1 - Privilege Escalation

Title source: llm
STIX 2.1

Description

An improper caller check vulnerability in Managed Provisioning prior to SMR APR-2021 Release 1 allows unprivileged application to install arbitrary application, grant device admin permission and then delete several installed application.

References (3)

Core 3
Core References
Vendor Advisory x_refsource_confirm
https://security.samsungmobile.com/securityUpdate.smsb
Vendor Advisory x_refsource_confirm
https://security.samsungmobile.com/

Scores

CVSS v3 7.1
EPSS 0.0018
EPSS Percentile 7.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N

Details

CWE
CWE-20 CWE-863
Status published
Products (4)
google/android 8.1
google/android 9.0
google/android 10.0
google/android 11.0
Published Apr 09, 2021
Tracked Since Feb 18, 2026