PT-2019-19674 · Google · Android Kernel

Publicado

2019-11-13

·

Atualizado

2021-07-21

·

CVE-2019-9467

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Android kernel
Description The issue is related to a possible kernel command injection in the Bootloader due to missing command sanitization. This could lead to a local elevation of privilege, with System execution privileges needed. User interaction is not required for exploitation.
Recommendations For Android kernel, consider applying a patch or fix that addresses the missing command sanitization issue in the Bootloader to prevent kernel command injection.

Correção

RCE

Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-9467

Produtos afetados

Android Kernel