PT-2017-1053 · Google+1 · Android+1
Published
2017-01-12
·
Updated
2017-01-19
·
CVE-2016-6782
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Android versions Kernel-3.10
Description
An elevation of privilege issue in the MediaTek driver could allow a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. The vulnerability is related to inadequate access control in the driver.
Recommendations
For Android version Kernel-3.10, consider restricting access to the kernel until a patch is available. As a temporary workaround, ensure that all privileged processes are secured to prevent initial compromise.
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Android
Mediatek