CVE-2017-0682: Critical severity Google Android vulnerability
Published Jul 5, 2017
·Updated
A remote code execution vulnerability in the Android media framework. Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-36588422.
Affected Software
4 affected components
Google Android=7.0
Google Android=7.1.1
Google Android=7.1.2
Google Android
Remediation
Patch Available
Event History
Jul 5, 2017
CVE Published
via Android·12:00 AM
Jul 6, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
DescriptionWeakness
Frequently Asked Questions
1
Which Android releases should be checked for exposure?
Check devices running Android 7.0, 7.1.1, or 7.1.2. The affected component is the Android media framework.
2
Does exploitation require user interaction or prior privileges?
The CVSS vector indicates that user interaction is required and that no privileges are required. It also lists a local attack vector.
3
What remediation is available?
A patch is available. The issue is identified by Android ID A-36588422.