Show plain JSON{"id": "CVE-2017-0576", "cveTags": [], "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 7.6, "accessVector": "NETWORK", "vectorString": "AV:N/AC:H/Au:N/C:C/I:C/A:C", "authentication": "NONE", "integrityImpact": "COMPLETE", "accessComplexity": "HIGH", "availabilityImpact": "COMPLETE", "confidentialityImpact": "COMPLETE"}, "acInsufInfo": false, "impactScore": 10.0, "baseSeverity": "HIGH", "obtainAllPrivilege": false, "exploitabilityScore": 4.9, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": true}], "cvssMetricV30": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "UNCHANGED", "version": "3.0", "baseScore": 7.0, "attackVector": "LOCAL", "baseSeverity": "HIGH", "vectorString": "CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H", "integrityImpact": "HIGH", "userInteraction": "REQUIRED", "attackComplexity": "HIGH", "availabilityImpact": "HIGH", "privilegesRequired": "NONE", "confidentialityImpact": "HIGH"}, "impactScore": 5.9, "exploitabilityScore": 1.0}]}, "published": "2017-04-07T22:59:01.467", "references": [{"url": "http://www.securityfocus.com/bid/97395", "source": "security@android.com"}, {"url": "http://www.securitytracker.com/id/1038201", "source": "security@android.com"}, {"url": "https://github.com/derrekr/android_security/commit/0dd1a733e60cf5239c0a185d4219ba2ef1118a8b", "source": "security@android.com"}, {"url": "https://source.android.com/security/bulletin/2017-04-01", "tags": ["Vendor Advisory"], "source": "security@android.com"}, {"url": "http://www.securityfocus.com/bid/97395", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.securitytracker.com/id/1038201", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "https://github.com/derrekr/android_security/commit/0dd1a733e60cf5239c0a185d4219ba2ef1118a8b", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "https://source.android.com/security/bulletin/2017-04-01", "tags": ["Vendor Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Deferred", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-190"}]}], "descriptions": [{"lang": "en", "value": "An elevation of privilege vulnerability in the Qualcomm crypto engine driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-33544431. References: QC-CR#1103089."}, {"lang": "es", "value": "Vulnerabilidad de elevaci\u00f3n de privilegios en el controlador de motor de cifrado de Qualcomm podr\u00eda permitir que una aplicaci\u00f3n maliciosa local ejecute c\u00f3digo arbitrario dentro del contexto del kernel. Este problema se califica como alto porque primero requiere comprometer un proceso privilegiado. Producto: Android. Versiones: Kernel-3.10, Kernel-3.18. ID de Android: A-33544431. Referencias: QC-CR#1103089."}], "lastModified": "2025-04-20T01:37:25.860", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:linux:linux_kernel:3.10:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1C37F47C-C217-4BCF-A758-14E1BDBAD63D"}, {"criteria": "cpe:2.3:o:linux:linux_kernel:3.18:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "364CAD86-F652-4B84-932A-A8D9146C9010"}], "operator": "OR"}]}], "sourceIdentifier": "security@android.com"}