ZeroHour

CVE-2011-1823

KEVmass

Privilege Escalation to Root via Netlink Spoofing in Android vold Daemon

CISA: Android OS Privilege Escalation Vulnerability

CVSS
EPSS
42%p99
Published
KEV added
AI analysis

The vold volume manager daemon in Android trusts messages arriving on a PF_NETLINK socket without authenticating their source, so a local process can send spoofed netlink messages to the daemon. A malicious app running on the device can abuse this trust to have vold execute code on its behalf with elevated privileges. A successful attacker gains root privileges, giving full control of the device and the ability to install software or modify the system. The flaw dates to 2011 and was weaponized in the GingerBreak rooting exploit and the Exploit.AndroidOS.Lotoor malware; CISA added it to the Known Exploited Vulnerabilities catalog on 2022-09-08, confirming in-the-wild exploitation. EPSS currently assigns a 41.6% probability of exploitation in the next 30 days (99th percentile), and the required action is to apply updates per vendor instructions.

What to do: Apply updates per vendor instructions as required by CISA's KEV listing, prioritizing legacy devices still running 2011-era Android that cannot receive patches, and retire or isolate them if updates are unavailable. Because this is a local privilege escalation, review devices that permit sideloading or untrusted apps and check rooted devices for signs of the Exploit.AndroidOS.Lotoor malware. Federal agencies should track the KEV remediation deadline.

Affected
Android OS
Estimated exposure
masshundreds of millions of Android devices historically (2011-era Android installed base); current count of still-vulnerable legacy devices unknown — The flaw affected the Android OS broadly at disclosure in 2011, when Android's global smartphone installed base was in the hundreds of millions, and no version range is provided to narrow the count.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The vold volume manager daemon in Android kernel trusts messages from a PF_NETLINK socket, which allows an attacker to execute code and gain root privileges. This vulnerability is associated with GingerBreak and Exploit.AndroidOS.Lotoor.

CISA Known Exploited Vulnerability
Affected
Android Android OS
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
Android
Products
Android OS
Weakness
CWE-189

In the news

No ingested article mentions this CVE yet.