PT-2016-1721 · Google · Android
Chengjia4574
+4
·
Published
2016-04-18
·
Updated
2016-04-20
·
CVE-2016-2411
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Android versions prior to 2016-04-01
Description
The issue is related to a Qualcomm Power Management kernel driver in Android, which allows attackers to gain privileges via a crafted application that leverages root access. This is due to insufficient input validation, which can be exploited by a remote attacker to elevate their privileges using a specially crafted application that utilizes root access.
Recommendations
For Android versions prior to 2016-04-01, consider restricting root access to minimize the risk of exploitation until a fix is available. As a temporary workaround, avoid using applications that require root access to reduce the potential for privilege escalation.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Android