ZeroHour

CVE-2017-18141

CVSS 3.0
7.8 high
EPSS
<1%p13
Published
()
Modified
Description

When a 3rd party TEE has been loaded it is possible for the non-secure world to create a secure monitor call which will give it access to privileged functions meant to only be accessible from the TEE in Snapdragon Automobile, Snapdragon Mobile and Snapdragon Wear in versions IPQ8074, MDM9206, MDM9607, MDM9635M, MDM9650, MDM9655, MSM8996AU, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 625, SD 632, SD 636, SD 650/52, SD 810, SD 820, SD 820A, SD 835, SDA660, SDM439, SDM630, SDM660, SDX24, Snapdragon_High_Med_2016.

Vendors
qualcomm
Products
ipq8074 firmware, mdm9206 firmware, mdm9607 firmware, mdm9635m firmware, mdm9650 firmware, mdm9655 firmware, msm8996au firmware, sd 210 firmware, sd 212 firmware, sd 205 firmware, sd 410 firmware, sd 412 firmware
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.