CVE-2016-8444: High severity android vulnerability
Published Jan 3, 2017
·Updated
An elevation of privilege vulnerability in the Qualcomm camera could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10. Android ID: A-31243641. References: QC-CR#1074310.
Affected Software
2 affected components
Google Android
Linux Linux Kernel=3.10
Event History
Jan 3, 2017
CVE Published
via Android·12:00 AM
Jan 12, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
DescriptionWeakness
Data Sourced
via NVD·08:59 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What must an attacker do before this issue can be exploited?
The issue requires a local malicious application and first requires compromise of a privileged process. Successful exploitation could then allow arbitrary code execution in the kernel context.
2
Which systems should be prioritized for review?
Android devices using Kernel-3.10 should be reviewed, particularly where local applications can be installed or a privileged process may already be compromised.