CVE-2017-0612Allocation of Resources Without Limits or Throttling in INC Android

Severity
7.0HIGHNVD
EPSS
0.2%
top 60.33%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 12
Latest updateMay 13

Description

An elevation of privilege vulnerability in the Qualcomm Secure Execution Environment Communicator driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.18. Android ID: A-34389303. References: QC-CR#1061845.

CVSS vector

CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.0 | Impact: 5.9

Affected Packages3 packages

CVEListV5google_inc/androidKernel-3.18

Patches

🔴Vulnerability Details

1
GHSA
GHSA-fx2q-3crh-8pjx: An elevation of privilege vulnerability in the Qualcomm Secure Execution Environment Communicator driver could enable a local malicious application to2022-05-13

📋Vendor Advisories

1
Android
CVE-2017-0612: Android Security Bulletin 2017-05-01 CVE: CVE-2017-0612 Severity: HIGH References: A-34389303 QC-CR#10618452017-05-01