CVE-2017-0562: Critical severity Google Android vulnerability
An elevation of privilege vulnerability in the MediaTek touchscreen driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: N/A. Android ID: A-30202425. References: M-ALPS02898189.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Android devices using the affected MediaTek touchscreen driver are exposed. The provided information does not identify specific Android versions or device models.
What does an attacker need to exploit it?
An attacker needs the ability to run a malicious application locally on the device and user interaction is required. The CVSS vector indicates no privileges are required before exploitation.
What is the potential impact of successful exploitation?
A successful exploit can execute arbitrary code in the kernel context, compromising confidentiality, integrity, and availability. The compromise may be permanent and may require reflashing the operating system to repair the device.