CVE-2017-0504
HIGHAndroid < 7.1.1 - Elevation of Privilege in MediaTek Components
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-0504. PoCs published by ScottyBauer.
AI-analyzed exploit summary This PoC exploits CVE-2017-0504, a vulnerability in the MediaTek kernel driver for Android. It triggers a buffer overflow by writing a malformed `st_cmd_head` structure with an invalid `data_len` (65534) to a device node, likely leading to a kernel crash or privilege escalation.
Description
An elevation of privilege vulnerability in MediaTek components, including the M4U driver, sound driver, touchscreen driver, GPU driver, and Command Queue driver, could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: N/A. Android ID: A-30074628. References: M-ALPS02829371.
Exploits (1)
This PoC exploits CVE-2017-0504, a vulnerability in the MediaTek kernel driver for Android. It triggers a buffer overflow by writing a malformed `st_cmd_head` structure with an invalid `data_len` (65534) to a device node, likely leading to a kernel crash or privilege escalation.
References (4)
Scores
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H