Elevation of Privilege Vulnerability in Android's HTC Sound Codec Driver
CVE-2016-6779

7HIGH

Key Information:

Vendor

Linux

Vendor
CVE Published:
12 January 2017

What is CVE-2016-6779?

An elevation of privilege vulnerability exists in the HTC sound codec driver for Android devices, allowing a local malicious application to execute arbitrary code with elevated privileges within the kernel. This vulnerability requires that the malicious application first compromise a privileged process, which could lead to further exploitation of the system. Users are advised to ensure that their devices are updated to mitigate the risks associated with this vulnerability.

Affected Version(s)

Android Kernel-3.10 Android Kernel-3.10

References

CVSS V3.1

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.