CVE-2017-11067 is a high-severity vulnerability affecting Google Android devices utilizing Qualcomm's MSM components, specifically within the Athdiag procfs entry. It allows a local attacker to achieve high impact on confidentiality, integrity, and availability due to an improper address sanity check leading to an out-of-range pointer offset. Despite its high CVSS score of 7.8, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage. This suggests a low current threat landscape, though the potential for local privilege escalation remains.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.0CPE matchmatch criteria | cpe:2.3:o:google:android:8.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.