CVE-2017-0799: High severity Google Android vulnerability
Published Sep 5, 2017
·Updated
A elevation of privilege vulnerability in the MediaTek lastbus. Product: Android. Versions: Android kernel. Android ID: A-36731602. References: M-ALPS03342072.
Affected Software
2 affected components
Google Android<=7.1.2
Google Android
Event History
Sep 5, 2017
CVE Published
via Android·12:00 AM
Data Sourced
via Android·12:00 AM
SeverityWeaknessAffected Software
Sep 8, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
The CVSS vector indicates local attack access and no privileges required, but user interaction is required. Successful exploitation can result in high impact to confidentiality, integrity, and availability.
2
Which systems are identified as affected?
The issue is identified in the MediaTek lastbus component of the Android kernel, for the Google Android product. The provided data does not identify specific Android release versions or affected device models.
3
How can I identify this issue in vendor tracking?
Use Android issue ID A-36731602 and reference M-ALPS03342072 when checking vendor advisories, device updates, or internal vulnerability records.