CISA Known Exploited Vulnerability

CVE-2011-1823

Android · Android OS

Android OS Privilege Escalation Vulnerability

Date added
BOD 22-01 due date
CWE CWE-189
Ransomware Unknown

CISA description

The vold volume manager daemon in Android kernel trusts messages from a PF_NETLINK socket, which allows an attacker to execute code and gain root privileges. This vulnerability is associated with GingerBreak and Exploit.AndroidOS.Lotoor.

Required action

Apply updates per vendor instructions.