CVE-2017-0802: High severity Google Android vulnerability
Published Sep 5, 2017
·Updated
A elevation of privilege vulnerability in the MediaTek kernel. Product: Android. Versions: Android kernel. Android ID: A-36232120. References: M-ALPS03384818.
Affected Software
2 affected components
Google Android<=7.1.2
Google Android
Event History
Sep 5, 2017
CVE Published
via Android·12:00 AM
Data Sourced
via Android·12:00 AM
SeverityWeaknessAffected Software
Sep 8, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The CVSS vector indicates local access is required, but no privileges are needed. Exploitation also requires user interaction.
2
What is the potential impact after successful exploitation?
Successful exploitation can result in elevation of privilege and has high impacts on confidentiality, integrity, and availability according to the CVSS vector.
3
Which systems are in scope?
The issue affects the MediaTek kernel in Android. The provided data identifies Google Android and refers to the Android kernel, without listing specific Android release versions or device models.