Junglewise Threat Intelligence

CVE-2014-9910: Broadcom Wi-Fi driver privilege escalation in Android

CVE-2014-9910 · Severity: high · CVSS 7 · Published 2017-01-18

Technologies: Google Android. Vendors: Google.

Executive brief

A security vulnerability in the Broadcom Wi-Fi driver used in Android devices could allow a malicious application to gain high-level system privileges. If exploited, an attacker could execute unauthorized code with kernel-level access, potentially leading to a full device compromise or the need to reinstall the operating system. This attack requires the malicious app to first compromise a privileged process on the device.

Technical details

An elevation of privilege vulnerability exists in the Broadcom Wi-Fi driver integrated into Android devices. The flaw is categorized under CWE-264 (Permissions, Privileges, and Access Controls) and allows a local attacker to execute arbitrary code with kernel privileges. Exploitation is considered complex as it requires the attacker to first compromise a privileged process and may involve user interaction. The vulnerability was addressed in the December 2016 Android Security Bulletin, with patches provided for affected devices running Android 7.1.0 and earlier.

Affected products

  • Google Android 7.1.0 and earlier

Timeline

  • 2016-11-07: other: Partners notified of the vulnerability
  • 2016-12-05: patched: Security bulletin published and patches released via AOSP
  • 2017-01-18: advisory: NVD advisory published

References

Related threats