Elevation of Privilege Vulnerability in libnl Allows Arbitrary Code Execution in Android Wi-Fi Service

Elevation of Privilege Vulnerability in libnl Allows Arbitrary Code Execution in Android Wi-Fi Service

CVE-2017-0553 · HIGH Severity

AV:N/AC:H/AU:N/C:C/I:C/A:C

An elevation of privilege vulnerability in libnl could enable a local malicious application to execute arbitrary code within the context of the Wi-Fi service. This issue is rated as Moderate because it first requires compromising a privileged process and is mitigated by current platform configurations. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-32342065. NOTE: this issue also exists in the upstream libnl before 3.3.0 library.

Learn more about our Cis Benchmark Audit For Google Android.