CVE-2016-8418 — Improper Access Control in Google Android
Severity
9.8CRITICALNVD
EPSS
3.6%
top 12.28%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 8
Latest updateMay 17
Description
A remote code execution vulnerability in the Qualcomm crypto driver could enable a remote attacker to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of remote code execution in the context of the kernel. Product: Android. Versions: N/A. Android ID: A-32652894. References: QC-CR#1077457.
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9
Affected Packages3 packages
🔴Vulnerability Details
2GHSA▶
GHSA-vv6x-5wf6-xh93: A remote code execution vulnerability in the Qualcomm crypto driver could enable a remote attacker to execute arbitrary code within the context of the↗2022-05-17
OSV▶
CVE-2016-8418: A remote code execution vulnerability in the Qualcomm crypto driver could enable a remote attacker to execute arbitrary code within the context of the↗2017-02-08
📋Vendor Advisories
1Android▶
CVE-2016-8418: Android Security Bulletin 2017-02-01
CVE: CVE-2016-8418
Severity: CRITICAL
References: A-32652894
QC-CR#1077457↗2017-02-01