CVE-2016-8418Improper Access Control in Google Android

Severity
9.8CRITICALNVD
EPSS
3.6%
top 12.28%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 8
Latest updateMay 17

Description

A remote code execution vulnerability in the Qualcomm crypto driver could enable a remote attacker to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of remote code execution in the context of the kernel. Product: Android. Versions: N/A. Android ID: A-32652894. References: QC-CR#1077457.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages3 packages

NVDgoogle/android6.0.1
CVEListV5google_inc/androidn/a

🔴Vulnerability Details

2
GHSA
GHSA-vv6x-5wf6-xh93: A remote code execution vulnerability in the Qualcomm crypto driver could enable a remote attacker to execute arbitrary code within the context of the2022-05-17
OSV
CVE-2016-8418: A remote code execution vulnerability in the Qualcomm crypto driver could enable a remote attacker to execute arbitrary code within the context of the2017-02-08

📋Vendor Advisories

1
Android
CVE-2016-8418: Android Security Bulletin 2017-02-01 CVE: CVE-2016-8418 Severity: CRITICAL References: A-32652894 QC-CR#10774572017-02-01