CVE-2017-0711: Critical severity Google Android vulnerability
Published Jul 5, 2017
·Updated
A elevation of privilege vulnerability in the MediaTek networking driver. Product: Android. Versions: Android kernel. Android ID: A-36099953. References: M-ALPS03206781.
Affected Software
2 affected components
Google Android=7.1.2
Google Android
Event History
Jul 5, 2017
CVE Published
via Android·12:00 AM
Jul 6, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
The CVSS vector indicates local access, no privileges, low attack complexity, and required user interaction. Exploitation is not described as remotely reachable over a network.
2
What is the potential impact of successful exploitation?
Successful exploitation can result in elevation of privilege and compromise of confidentiality, integrity, and availability. The CVSS vector rates all three impacts as high.
3
Which component should be investigated when determining exposure?
Investigate devices using the MediaTek networking driver in an Android kernel. The provided data does not identify specific device models or affected kernel versions.