CVE-2017-0801: High severity Google Android vulnerability
Published Sep 5, 2017
·Updated
A elevation of privilege vulnerability in the MediaTek libmtkomxvdec. Product: Android. Versions: Android kernel. Android ID: A-38447970. References: M-ALPS03337980.
Affected Software
2 affected components
Google Android<=7.1.2
Google Android
Event History
Sep 5, 2017
CVE Published
via Android·12:00 AM
Data Sourced
via Android·12:00 AM
SeverityWeaknessAffected Software
Sep 8, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
DescriptionWeakness
Mar 9, 58506
Event
07:39 AM
Frequently Asked Questions
1
What access and user action are required for exploitation?
The CVSS vector indicates local attack access, no prior privileges, and required user interaction. The available data does not indicate a network-based attack path.
2
What could a successful exploit affect?
The CVSS assessment rates confidentiality, integrity, and availability impact as high. A successful exploit could therefore expose data, alter data, or disrupt device operation.