PT-2017-1883 · Google · Android
Gal Beniamini
·
Published
2017-04-07
·
Updated
2019-10-03
·
CVE-2017-0571
CVSS v2.0
7.6
High
| Vector | AV:N/AC:H/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Android versions Kernel-3.10, Kernel-3.18
Description
An elevation of privilege issue in the Broadcom Wi-Fi driver could allow a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. The vulnerability is related to insufficient access control in the Wi-Fi driver, which could be exploited by a remote attacker using a special application to execute arbitrary code in the context of the kernel.
Recommendations
For Android versions Kernel-3.10, Kernel-3.18, consider disabling the Wi-Fi driver until a patch is available to prevent potential exploitation.
As a temporary workaround, restrict access to the kernel to minimize the risk of arbitrary code execution.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Android