CVE-2017-0395: Medium severity android vulnerability
An elevation of privilege vulnerability in Contacts could enable a local malicious application to silently create contact information. This issue is rated as Moderate because it is a local bypass of user interaction requirements (access to functionality that would normally require either user initiation or user permission). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1. Android ID: A-32219099.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-0395?
CVE-2017-0395 is rated as Moderate due to its ability to allow a local malicious application to bypass user interaction requirements.
How do I fix CVE-2017-0395?
To mitigate CVE-2017-0395, it is recommended to update your Android device to the latest software version that contains the security patch.
Which Android versions are affected by CVE-2017-0395?
CVE-2017-0395 affects multiple versions of Android, including 4.0 through 7.1.0.
What kind of vulnerability is CVE-2017-0395?
CVE-2017-0395 is classified as an elevation of privilege vulnerability in the Contacts application.
Can CVE-2017-0395 be exploited remotely?
No, CVE-2017-0395 requires local access to the device to be exploited.