First published: Tue Jan 03 2017(Updated: )
An elevation of privilege vulnerability in the bootloader could enable a local attacker to execute arbitrary modem commands on the device. This issue is rated as High because it is a local permanent denial of service (device interoperability: completely permanent or requiring re-flashing the entire operating system). Product: Android. Versions: N/A. Android ID: A-30308784.
Credit: security@android.com
Affected Software | Affected Version | How to fix |
---|---|---|
Android | <=7.1.0 | |
Android | ||
<=7.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-8467 is rated as High due to its potential for local elevation of privilege that could lead to a permanent denial of service.
Fixing CVE-2016-8467 involves updating to a version of Android higher than 7.1.0 or applying relevant security patches provided by Google.
CVE-2016-8467 is classified as an elevation of privilege vulnerability in the Android bootloader.
CVE-2016-8467 affects devices running Android versions up to and including 7.1.0.
Yes, CVE-2016-8467 can lead to data loss as it allows an attacker to execute arbitrary modem commands, potentially resulting in a complete loss of device functionality.