EXPOSURES › CVE-2011-1823
CVE-2011-1823
HIGH ⌖ ON CISA KEV · EXPLOITEDAndroid OS kernel vold daemon allowed remote code execution via a Netlink socket, leading to root privileges
An Android OS kernel vulnerability allowed attackers to execute arbitrary code and gain root access via the vold volume manager daemon over a Netlink socket, as exploited by GingerBreak and Exploit.AndroidOS.Lotoor. This posed a high risk to DIB organizations due to the ease of exploitation and the potential for unauthorized access to sensitive data and system control.
Shame score — Ease of exploitation and high risk of unauthorized access to sensitive data and system control
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
The vold volume manager daemon in Android kernel trusts messages from a PF_NETLINK socket, which allows an attacker to execute code and gain root privileges. This vulnerability is associated with GingerBreak and Exploit.AndroidOS.Lotoor.