CVE-2017-7115
HIGHiPhone OS < 10.3.3 and tvOS < 10.2.2 - Remote Code Execution or Denial of Service via Wi-Fi Race Condition
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-7115. PoCs published by Google Security Research.
AI-analyzed exploit summary This exploit leverages a Wi-Fi vulnerability (CVE-2017-7115) to achieve arbitrary read/write access to physical memory on iOS devices. It uses a modified hostapd to inject crafted 802.11k frames and executes shellcode to gain control over the target device.
Description
An issue was discovered in certain Apple products. iOS before 11 is affected. tvOS before 11 is affected. The issue involves the "Wi-Fi" component. It might allow remote attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via crafted Wi-Fi traffic that leverages a race condition.
Exploits (1)
This exploit leverages a Wi-Fi vulnerability (CVE-2017-7115) to achieve arbitrary read/write access to physical memory on iOS devices. It uses a modified hostapd to inject crafted 802.11k frames and executes shellcode to gain control over the target device.
References (6)
Scores
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H