Arbitrary Code Execution Vulnerability in Samsung Mobile Devices
CVE-2017-18020
8.4HIGH
What is CVE-2017-18020?
On Samsung mobile devices running Lollipop (5.x), Marshmallow (6.x), and Nougat (7.x) operating systems utilizing Exynos chipsets, a security flaw exists in the S Boot. The vulnerability arises from a lack of size verification when transferring ramfs data into memory, enabling potential attackers to execute arbitrary code within the bootloader.