CVE-2017-0404: High severity android vulnerability
Published Jan 3, 2017
·Updated
An elevation of privilege vulnerability in the kernel sound subsystem could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-32510733.
Affected Software
3 affected components
Google Android
Linux Linux Kernel=3.10
Linux Linux Kernel=3.18
Event History
Jan 3, 2017
CVE Published
via Android·12:00 AM
Jan 12, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
DescriptionWeakness
Data Sourced
via NVD·08:59 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
Which systems are identified as affected?
The affected product is Android, specifically systems using Kernel-3.10 or Kernel-3.18. The issue is in the kernel sound subsystem.
2
What access or preconditions does exploitation require?
Exploitation requires local execution by a malicious application and user interaction. It also first requires compromise of a privileged process before arbitrary code can be executed in the kernel context.