ZeroHour

CVE-2017-18302

CVSS 3.0
4.7 medium
EPSS
<1%p7
Published
()
Modified
Description

In Snapdragon (Automobile ,Mobile) in version MSM8996AU, SD 425, SD 427, SD 430, SD 435, SD 450, SD 625, SD 650/52, SD 820, SD 820A, SD 835, SDA660, SDM429, SDM439, SDM630, SDM632, SDM636, SDM660, Snapdragon_High_Med_2016, a crafted HLOS client can modify the structure in memory passed to a QSEE application between the time of check and the time of use, resulting in arbitrary writes to TZ kernel memory regions.

Vendors
qualcomm
Products
msm8996au firmware, sd425 firmware, sd427 firmware, sd430 firmware, sd435 firmware, sd450 firmware, sd625 firmware, sd650 firmware, sd652 firmware, sd820 firmware, sd820a firmware, sd835 firmware
Weakness
CWE-362
Vector
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.