CVE-2016-6717: High severity Google Android vulnerability
An elevation of privilege vulnerability in Mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-11-01, and 7.0 before 2016-11-01 could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as Moderate because it first requires exploitation of a separate vulnerability. Android ID: A-31350239.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-6717?
CVE-2016-6717 is classified as an elevation of privilege vulnerability.
How do I fix CVE-2016-6717?
To fix CVE-2016-6717, upgrade your Android device to a version 4.4.4 or later, or 5.0.2 or later.
Which versions of Android are affected by CVE-2016-6717?
CVE-2016-6717 affects Android versions 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-11-01, and 7.0 before 2016-11-01.
What could an attacker achieve by exploiting CVE-2016-6717?
An attacker exploiting CVE-2016-6717 could execute arbitrary code within the context of a privileged process.
Who is the vendor of the product affected by CVE-2016-6717?
The vendor of the product affected by CVE-2016-6717 is Google, specifically their Android operating system.