CVE-2012-4220 describes a critical vulnerability in the Qualcomm Innovation Center (QuIC) Diagnostics kernel-mode driver for Android versions 2.3 through 4.2. Attackers can exploit this flaw by using crafted arguments in a local diagchar_ioctl call from an application, potentially leading to arbitrary code execution or a denial of service due to an incorrect pointer dereference. With a CVSS score of 6.8 (medium severity), this vulnerability has a network attack vector, medium attack complexity, and can result in partial confidentiality, integrity, and availability impacts. While no public exploit code is available via Metasploit, Nuclei, or ExploitDB, the vulnerability has garnered significant community discussion and media coverage, including mentions in articles about Android spyware like Tizi, suggesting its potential relevance in real-world attacks despite its "Inactive" Hot List status.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.3CPE matchmatch criteria | cpe:2.3:o:google:android:2.3:*:*:*:*:*:*:* | ||
2.3CPE matchmatch criteria | cpe:2.3:o:google:android:2.3:rev1:*:*:*:*:*:* | ||
2.3.1CPE matchmatch criteria | cpe:2.3:o:google:android:2.3.1:*:*:*:*:*:*:* | ||
2.3.2CPE matchmatch criteria | cpe:2.3:o:google:android:2.3.2:*:*:*:*:*:*:* | ||
2.3.3CPE matchmatch criteria | cpe:2.3:o:google:android:2.3.3:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.