ZeroHour

CVE-2017-18144

CVSS 3.0
9.8 critical
EPSS
1%p67
Published
()
Modified
Description

In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Mobile and Snapdragon Wear MSM8909W, SD 210/SD 212/SD 205, SD 450, SD 615/16/SD 415, SD 625, SD 650/52, SD 820, SD 835, SD 845, while processing the retransmission of WPA supplicant command send failures, there is a make after break of the connection to WPA supplicant where the local pointer is not properly updated. If the WPA supplicant command transmission fails, a Use After Free condition will occur.

Vendors
qualcomm
Products
msm8909w firmware, sd 210 firmware, sd 212 firmware, sd 205 firmware, sd 450 firmware, sd 615 firmware, sd 616 firmware, sd 415 firmware, sd 625 firmware, sd 650 firmware, sd 652 firmware, sd 820 firmware
Weakness
CWE-416
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.