CVE-2016-6772
HIGHAndroid 5.0.2 5.1.1 6.0 6.0.1 7.0 - Elevation of Privilege via Wi-Fi
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2016-6772. PoCs published by Google Security Research.
AI-analyzed exploit summary This exploit demonstrates a stack-based buffer overflow in the `android_net_wifi_setHotlist` function due to lack of validation on `params.num_bssid`, allowing an attacker with system_api_service access to corrupt the stack and potentially achieve remote code execution.
Description
An elevation of privilege vulnerability in Wi-Fi could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0. Android ID: A-31856351.
Exploits (1)
This exploit demonstrates a stack-based buffer overflow in the `android_net_wifi_setHotlist` function due to lack of validation on `params.num_bssid`, allowing an attacker with system_api_service access to corrupt the stack and potentially achieve remote code execution.
References (4)
Scores
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H