Google Android CVE-2014-7911 Local Privilege Escalation Vulnerability
BID:71176
Info
Google Android CVE-2014-7911 Local Privilege Escalation Vulnerability
| Bugtraq ID: | 71176 |
| Class: | Serialization Error |
| CVE: |
CVE-2014-7911 |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 19 2014 12:00AM |
| Updated: | Feb 16 2015 12:02AM |
| Credit: | Jann Horn |
| Vulnerable: |
Google Android 3.1.4 Google Android 2.3.5 Google Android 2.2.3 Google Android 3.2 Google Android 3.0 Google Android 2.3.4 Google Android 2.3.3 Google Android 2.3.2 Google Android 2.3.1 Google Android 2.3 Rev1 Google Android 2.2.2 Google Android 2.2.1 Google Android 2.2 Rev1 Google Android 2.2 Google Android 2.1 Google Android 1.6 Google Android 1.5 |
| Not Vulnerable: | |
Discussion
Google Android CVE-2014-7911 Local Privilege Escalation Vulnerability
Google Android is prone to a local privilege-escalation vulnerability.
Local attackers can exploit this issue to execute arbitrary code in the context of the 'system_server' process and gain elevated privileges.
Versions prior to Android 5.0 are vulnerable.
Google Android is prone to a local privilege-escalation vulnerability.
Local attackers can exploit this issue to execute arbitrary code in the context of the 'system_server' process and gain elevated privileges.
Versions prior to Android 5.0 are vulnerable.
Exploit / POC
Google Android CVE-2014-7911 Local Privilege Escalation Vulnerability
The following proof-of-concept code is available:
The following proof-of-concept code is available:
Solution / Fix
Google Android CVE-2014-7911 Local Privilege Escalation Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Google Android CVE-2014-7911 Local Privilege Escalation Vulnerability
References:
References:
- Android Homepage (Android)