Junglewise Threat Intelligence

CVE-2014-9909: Broadcom Wi-Fi driver privilege escalation in Android

CVE-2014-9909 · Severity: high · CVSS 7 · Published 2017-01-18

Technologies: Google Android. Vendors: Google.

Executive brief

A security vulnerability in the Broadcom Wi-Fi driver used in Android devices could allow a malicious application to gain deep access to the device's operating system. If exploited, an attacker could execute code with kernel-level privileges, potentially leading to a full device compromise or permanent damage requiring a factory reset. This attack is difficult to perform because it requires the attacker to first compromise a separate, highly privileged process on the device.

Technical details

An elevation of privilege vulnerability exists in the Broadcom Wi-Fi driver component of the Android operating system. The flaw is categorized under CWE-264 (Permissions, Privileges, and Access Controls) and stems from improper validation or handling within the driver code. A local attacker can exploit this by using a malicious application to execute arbitrary code with kernel-level privileges. However, the attack complexity is high as it requires the attacker to have already compromised a privileged process. Google addressed this issue in the December 2016 Android Security Bulletin with patch levels 2016-12-01 or later.

Affected products

  • Google Android 7.1.0 and earlier

Timeline

  • 2016-11-07: other: Partners notified of the vulnerability
  • 2016-12-05: patched: Android Security Bulletin published and patches released
  • 2017-01-18: advisory: NVD advisory published

References

Related threats