CVE-2017-18154 is a high-severity vulnerability affecting MediaServer in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) that utilize the Linux Kernel. A malicious actor could exploit this flaw by sending a specially crafted binder request, leading to an arbitrary unmap operation. With a CVSS score of 7.8 (High), this vulnerability allows for high confidentiality, integrity, and availability impacts with low attack complexity and privileges. There is currently no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:google:android:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.