CVE-2017-0700: Critical severity Google Android vulnerability
Published Jul 5, 2017
·Updated
A remote code execution vulnerability in the Android system ui. Product: Android. Versions: 7.1.1, 7.1.2. Android ID: A-35639138.
Affected Software
3 affected components
Google Android=7.1.1
Google Android=7.1.2
Google Android
Remediation
Patch Available
Event History
Jul 5, 2017
CVE Published
via Android·12:00 AM
Jul 6, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
DescriptionWeakness
Frequently Asked Questions
1
Which Android versions are identified as affected?
The affected versions listed are Android 7.1.1 and 7.1.2. Other Android versions are not identified in the provided data.
2
What does an attacker need to exploit this issue?
The CVSS vector indicates local attack access, low attack complexity, no required privileges, and required user interaction. Successful exploitation can affect confidentiality, integrity, and availability at high impact.
3
What is the recommended remediation?
A patch is available. Apply the available Android security update for the affected device or build.