PT-2016-1721 · Google · Android

Chengjia4574

+4

·

Published

2016-04-18

·

Updated

2016-04-20

·

CVE-2016-2411

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Android versions prior to 2016-04-01
Description The issue is related to a Qualcomm Power Management kernel driver in Android, which allows attackers to gain privileges via a crafted application that leverages root access. This is due to insufficient input validation, which can be exploited by a remote attacker to elevate their privileges using a specially crafted application that utilizes root access.
Recommendations For Android versions prior to 2016-04-01, consider restricting root access to minimize the risk of exploitation until a fix is available. As a temporary workaround, avoid using applications that require root access to reduce the potential for privilege escalation.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2016-01047
CVE-2016-2411

Affected Products

Android