CVE-2017-14889

HIGH

Android - Remote Code Execution via WMI Descriptor Pool Index

Title source: llm
STIX 2.1

Description

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, due to the lack of a range check on the array index into the WMI descriptor pool, arbitrary address execution may potentially occur in the process mgmt completion handler.

Scores

CVSS v3 7.8
EPSS 0.0020
EPSS Percentile 9.8%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-129
Status published
Products (1)
google/android
Published Mar 16, 2018
Tracked Since Feb 18, 2026