Skip to content
COOEY

EXPOSURES › CVE-2011-1823

CVE-2011-1823

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-09-08 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2011-1823 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 exploited-in-wildunpatched

Android OS kernel vold daemon allowed remote code execution via a Netlink socket, leading to root privileges

An Android OS kernel vulnerability allowed attackers to execute arbitrary code and gain root access via the vold volume manager daemon over a Netlink socket, as exploited by GingerBreak and Exploit.AndroidOS.Lotoor. This posed a high risk to DIB organizations due to the ease of exploitation and the potential for unauthorized access to sensitive data and system control.

Shame score — Ease of exploitation and high risk of unauthorized access to sensitive data and system control

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

The vold volume manager daemon in Android kernel trusts messages from a PF_NETLINK socket, which allows an attacker to execute code and gain root privileges. This vulnerability is associated with GingerBreak and Exploit.AndroidOS.Lotoor.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.