CVE-2016-10277
high
CVSS v3
7.8
CVSS v2
9.3
VIR risk
7.8
Description
An elevation of privilege vulnerability in the Motorola bootloader could enable a local malicious application to execute arbitrary code within the context of the bootloader. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-33840490.
Predictions
Exploit likelihood
75%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: security@android.com — https://source.android.com/security/bulletin/2017-05-01
Exploits
Exploit-DB
- EDB-42601 · local · android
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| linux-kernel | 3.10 | affected | |
| linux-kernel | 3.18 | affected | |
References
CWEs
CWE-264
Verify integrity in audit chain (admin only). AS-IS.