Vulnerability Name:

CCN-64488

Published:2010-12-30
Updated:2010-12-30
Summary:Open Handset Alliance Android could allow a remote attacker gain elevated privileges on the system, caused by an error in the Zygote/Dalvik virtual machine framework. A remote attacker could exploit this vulnerability to gain root privileges on the device.
CVSS v3 Severity:9.6 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Exploitability Metrics:Attack Vector (AV): Adjacent
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:8.3 High (CCN CVSS v2 Vector: AV:A/AC:L/Au:N/C:C/I:C/A:C)
6.9 Medium (CCN Temporal CVSS v2 Vector: AV:A/AC:L/Au:N/C:C/I:C/A:C/E:F/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Adjacent_Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Consequences:Gain Privileges
References:Source: CCN
Type: c-skills blog, Thursday, December 30, 2010
Zygote trickery -- 743C 27C3 release

Source: CCN
Type: Open Handset Alliance Web site
Android

Source: CCN
Type: BID-45650
Open Handset Alliance Android Zygote Privilege Escalation Vulnerability

Source: XF
Type: UNKNOWN
android-zygote-privilege-escalation(64488)

Vulnerable Configuration:Configuration CCN 1:
  • cpe:/o:google:android:2.2:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    google android 2.2