CVE-2017-6292 is a high-severity vulnerability affecting Android devices before the 2018-06-05 security patch level, specifically within the NVIDIA TLZ TrustZone. It involves an integer overflow leading to an out-of-bounds write, which could allow a local attacker to escalate privileges within the TrustZone without user interaction or additional execution privileges. The CVSS score of 7.8 (HIGH) reflects the significant impact on confidentiality, integrity, and availability. While no active exploitation, public exploit code, or significant community discussion has been observed, the vulnerability poses a substantial risk if exploited.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:google:android:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.