CVE-2017-0613Improper Input Validation in INC Android

Severity
7.0HIGHNVD
EPSS
0.2%
top 61.22%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 12
Latest updateMay 13

Description

An elevation of privilege vulnerability in the Qualcomm Secure Execution Environment Communicator driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-35400457. References: QC-CR#1086140.

CVSS vector

CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.0 | Impact: 5.9

Affected Packages3 packages

NVDlinux/linux_kernel3.10, 3.18+1
CVEListV5google_inc/androidKernel-3.10, Kernel-3.18+1

Patches

🔴Vulnerability Details

1
GHSA
GHSA-2ggq-fwmx-v8g8: An elevation of privilege vulnerability in the Qualcomm Secure Execution Environment Communicator driver could enable a local malicious application to2022-05-13

📋Vendor Advisories

1
Android
CVE-2017-0613: Android Security Bulletin 2017-05-01 CVE: CVE-2017-0613 Severity: HIGH References: A-35400457 QC-CR#10861402017-05-01