CVE-2017-11073 is a high-severity vulnerability affecting Android devices utilizing Qualcomm's MSM components, including Android for MSM, Firefox OS for MSM, and QRD Android. The flaw allows a local attacker to map kernel memory to user space via the /proc/ath_pktlog/cld interface, leading to potential compromise of confidentiality, integrity, and availability. With a CVSS score of 7.8, exploitation is considered low complexity and does not require user interaction. While no public exploits or active exploitation have been identified, and community discussion is minimal, the vulnerability presents a significant risk to affected systems.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:google:android:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.