PT-2017-1883 · Google · Android

Gal Beniamini

·

Published

2017-04-07

·

Updated

2019-10-03

·

CVE-2017-0571

CVSS v2.0

7.6

High

VectorAV:N/AC:H/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Android versions Kernel-3.10, Kernel-3.18
Description An elevation of privilege issue in the Broadcom Wi-Fi driver could allow a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. The vulnerability is related to insufficient access control in the Wi-Fi driver, which could be exploited by a remote attacker using a special application to execute arbitrary code in the context of the kernel.
Recommendations For Android versions Kernel-3.10, Kernel-3.18, consider disabling the Wi-Fi driver until a patch is available to prevent potential exploitation. As a temporary workaround, restrict access to the kernel to minimize the risk of arbitrary code execution.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2017-01043
CVE-2017-0571

Affected Products

Android