Android Root Detection Vulnerability in Airwatch Agent by VMware
CVE-2017-4895

8.8HIGH

Key Information:

Vendor
Vmware
Vendor
CVE Published:
10 May 2017

Summary

The Airwatch Agent for Android contains a significant vulnerability that may enable malicious actors to circumvent root detection mechanisms. When successfully exploited, this flaw allows an enrolled device to bypass critical security controls imposed by Airwatch, granting unauthorized access to sensitive data and the potential to manipulate local security settings. Organizations using this software should implement necessary measures to mitigate the risk posed by this vulnerability.

Affected Version(s)

Airwatch Agent x.x

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.