CVE-2017-0831: Critical severity Google Android vulnerability
Published Nov 6, 2017
·Updated
An elevation of privilege vulnerability in the Android framework (window manager). Product: Android. Versions: 8.0. Android ID: A-37442941.
Affected Software
2 affected components
Google Android=8.0
Google Android
Remediation
Patch Available
Event History
Nov 6, 2017
CVE Published
via Android·12:00 AM
Nov 16, 2017
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
DescriptionWeakness
Frequently Asked Questions
1
Which devices should be prioritized for remediation?
Devices running Android 8.0 should be prioritized, as this is the affected version identified for Google Android.
2
What access does an attacker need to exploit this issue?
The CVSS vector indicates local access is required, no privileges are required, and user interaction is required.
3
What could a successful exploit allow?
A successful exploit could result in high impact to confidentiality, integrity, and availability.
4
How can I determine whether an asset is affected?
Check whether the device is running Android 8.0. The issue is tracked under Android ID A-37442941.
5
Is a fix available?
Yes. A patch is available.