CVE-2022-24480: Outlook for Android Elevation of Privilege Vulnerability

Overview

Severity
Medium (CVSS 6.3)
CVSS Vector
CVSS:3.1/AV:P/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Category
Elevation of Privilege
Exploit Status
Not Exploited
Exploitation Likelihood
Less Likely
Patch Tuesday
2022-Dec
Released
2022-12-13
Last Updated
2023-04-14
EPSS Score
0.94% (percentile: 76.2%)

FAQ

According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability? Successful exploitation of this vulnerability requires an attacker to physically access the target device. To gain access, an attacker must acquire the device after being unlocked by a legitimate user (target of opportunity) or possess the ability to pass device authentication or password protection mechanisms. According to the CVSS metric, privileges required is low (PR:L). What does that mean for this vulnerability? Modern mobile devices include authentication or password protection mechanisms which an attacker must be able to satisfy before gaining access to the target device. What privileges could be gained by an attacker who successfully exploited the vulnerability? An attacker with physical access to an unlocked device could bypass the application's biometric authentication, which effectively disables the application lock and gives the attacker full access. Is the update for Microsoft Outlook for Android listed in this vulnerability currently available? The security update for Microsoft Outlook for Android is not immediately available. The update will be released as soon as possible, and when it is available, customers will be notified via a revision to this CVE information.

Affected Products (1)

Apps

  • Microsoft Outlook for Android

Security Updates (1)

Acknowledgments

Eugene, Andr.Ess

Revision History

  • 2022-12-13: Information published.
  • 2022-12-15: Added FAQ to explain that the security update Outlook for Android is not immediately available, and that customers will be notified via a revision to the CVE when the update is available.
  • 2023-01-17: Microsoft is announcing the availability of the security update for Microsoft Outlook for Android. Customers running Outlook for Android should install the update for their product to be protected from this vulnerability. See the Security Updates table for the download link. Customers whose devices are configured to receive automatic updates do not need to take any further action.
  • 2023-04-14: Added FAQ information. This is an informational change only.