PT-2017-2162 · Google · Android

Published

2017-05-12

·

Updated

2019-10-03

·

CVE-2017-0619

CVSS v2.0

7.6

High

VectorAV:N/AC:H/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Android versions Kernel-3.10
Description The issue is related to insufficient access control in the Qualcomm pin controller driver of the Android operating system. It allows a remote attacker to execute arbitrary code in the context of the kernel by exploiting a local malicious application. This problem is considered high severity because it first requires compromising a privileged process.
Recommendations For Android version Kernel-3.10, consider restricting access to the Qualcomm pin controller driver until a patch is available. As a temporary workaround, ensure that all privileged processes are thoroughly monitored and secured to prevent initial compromise.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2017-01355
CVE-2017-0619

Affected Products

Android