PT-2018-1959 · Google+1 · Android Kernel+3

Publicado

2018-12-03

·

Atualizado

2019-10-03

·

CVE-2018-9567

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Android kernel
Description The issue is related to a bug in the verified boot process on Pixel devices, where the same certificate fingerprint is shown despite the use of different signing keys. This could lead to local escalation of privilege if the certificate fingerprints are relied upon to determine the OS version, requiring System execution privileges. No user interaction is needed for exploitation. The vulnerability is also associated with errors in the certificate authentication procedure of the HTC Bootloader component in the Android operating system.
Recommendations For Android kernel, consider implementing additional verification measures to ensure the authenticity of the OS version, rather than relying solely on certificate fingerprints, until a patch is available. As a temporary workaround, restrict access to System execution privileges to minimize the risk of exploitation.

Correção

Improper Certificate Validation

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2018-01566
CVE-2018-9567

Produtos afetados

Android
Android Kernel
Htc Bootloader
Pixel