PT-2017-1053 · Google+1 · Android+1

Published

2017-01-12

·

Updated

2017-01-19

·

CVE-2016-6782

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Android versions Kernel-3.10
Description An elevation of privilege issue in the MediaTek driver could allow a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. The vulnerability is related to inadequate access control in the driver.
Recommendations For Android version Kernel-3.10, consider restricting access to the kernel until a patch is available. As a temporary workaround, ensure that all privileged processes are secured to prevent initial compromise.

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2017-00122
CVE-2016-6782

Affected Products

Android
Mediatek