CVE-2017-0329 is an elevation of privilege vulnerability affecting the NVIDIA boot and power management processor driver in Android devices running Linux Kernel 3.18. A local malicious application could exploit this to execute arbitrary code within the boot and power management processor, but it first requires compromising a privileged process. Rated High with a CVSS score of 7.0, this vulnerability has a local attack vector and high attack complexity, as user interaction is required and a privileged process must already be compromised. Successful exploitation could lead to high impacts on confidentiality, integrity, and availability. There is currently no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. The vulnerability has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.18CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:3.18:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.0 Bluesky, 0.1 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.