Description
An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-34198729. References: B-RB#110666.
In plain language
AI Worth attentionCVE-2017-0569 is a Broadcom Wi‑Fi driver bug that lets a malicious app boost privileges to run code inside the phone’s kernel, usually by tricking the user to interact; this matters mainly for Android devices that have not been updated with the April 2017 security fixes.
CVE-2017-0569 is a local elevation of privilege in the Broadcom Wi‑Fi driver that can be triggered when a user interacts with a malicious app, allowing the attacker to run arbitrary code with kernel permissions.
What to do now
- Check whether the affected Android device(s) have the Android security patch level from 2017-04-01 or later (or the vendor’s equivalent security update).
- If not patched, plan an immediate OS/kernel update to a build that includes the fixes from the Android Security Bulletin (2017-04-01).
- After updating, verify the device reports the updated security patch level and that Wi‑Fi remains stable in normal use.
CVSS Vector Breakdown
AV:LAttack VectorAC:HAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2017-0569 and every CVE in our database. Create a free account — no credit card required.
Create Free Account