SB2022020854 - Security features bypass in Microsoft OneDrive for Android
Published: February 8, 2022
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Security features bypass (CVE-ID: CVE-2022-23255)
The vulnerability allows a local user to compromsie the target system.
The vulnerability exists due to an error in Microsoft OneDrive for Android. An authenticated attacker with physical access can bypass the authentication to access OneDrive files.
Remediation
Install update from vendor's website.