CVE-2017-0803: High severity Google Android vulnerability
Published Sep 5, 2017
·Updated
A elevation of privilege vulnerability in the MediaTek accessory detector driver. Product: Android. Versions: Android kernel. Android ID: A-36136137. References: M-ALPS03361477.
Affected Software
2 affected components
Google Android<=7.1.2
Google Android
Event History
Sep 5, 2017
CVE Published
via Android·12:00 AM
Data Sourced
via Android·12:00 AM
SeverityWeaknessAffected Software
Sep 8, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What access would an attacker need to exploit this issue?
The CVSS vector indicates local attack access, no privileges required, and user interaction is required. Successful exploitation could affect confidentiality, integrity, and availability.
2
Which systems are most relevant for triage?
The issue is in the MediaTek accessory detector driver and is identified as affecting the Android kernel. Android deployments using that driver should be prioritized for review.