Vulnerabilities > CVE-2017-0604 - Always-Incorrect Control Flow Implementation vulnerability in Google Android

047910
CVSS 9.3 - CRITICAL
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
google
CWE-670
critical

Summary

An elevation of privilege vulnerability in the kernel Qualcomm power driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: N/A. Android ID: A-35392981. References: QC-CR#826589.

The Hacker News

idTHN:B88414903959B85E02F9A824CFE6698A
last seen2018-01-27
modified2017-05-03
published2017-05-02
reporterSwati Khandelwal
sourcehttps://thehackernews.com/2017/05/android-security-update.html
titleGoogle Patches 6 Critical Android Mediaserver Bugs in May Security Update