CVE-2024-30059HighCVSS 6.1

Microsoft Intune for Android Mobile Application Management Tampering Vulnerability

Published
May 14, 2024
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

How could an attacker exploit this vulnerability? To exploit this vulnerability, an attacker requires access to a rooted target device and must disable certain components of the Intune Mobile Application Manager which do not fully impact availability. An attacker could then gain access to sensitive files based on the targeted device's privileges but does not provide the ability to alter data.

How do I know if I am affected by this vulnerability? Customers using Microsoft Intune Mobile Application Management features enabled by the Intune App SDK for Android are affected by this vulnerability. Customers who do not have auto-updates enabled need to update the Intune Company Portal to version 5.0.6215.0 or higher to be protected from this vulnerability.

🎯 Affected products1

  • Microsoft Intune Mobile Application Management for Android

✅ Remediation

KBRelease Notes (Security Update) — fixed build 5.0.6215.0

🔗 References (3)