// For flags

CVE-2011-1149

 

Severity Score

7.2
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Android before 2.3 does not properly restrict access to the system property space, which allows local applications to bypass the application sandbox and gain privileges, as demonstrated by psneuter and KillingInTheNameOf, related to the use of Android shared memory (ashmem) and ASHMEM_SET_PROT_MASK.

Android anterior a v2.3 no restringe de forma adecuada el acceso al espacio de propiedad del sistema, lo que permite a las aplicaciones locales evitar los privilegios de recinto de seguridad de aplicaciones y obtener privilegios, como lo demuestra psneuter y KillingInTheNameOf, relacionado con el uso de la memoria compartida Android (ashmem) y ASHMEM_SET_PROT_MASK.

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2011-03-03 CVE Reserved
  • 2011-04-21 CVE Published
  • 2023-05-10 EPSS Updated
  • 2024-08-06 CVE Updated
  • 2024-08-06 First Exploit
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-264: Permissions, Privileges, and Access Controls
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Google
Search vendor "Google"
Android
Search vendor "Google" for product "Android"
<= 2.2.2
Search vendor "Google" for product "Android" and version " <= 2.2.2"
-
Affected
Google
Search vendor "Google"
Android
Search vendor "Google" for product "Android"
1.5
Search vendor "Google" for product "Android" and version "1.5"
-
Affected
Google
Search vendor "Google"
Android
Search vendor "Google" for product "Android"
1.6
Search vendor "Google" for product "Android" and version "1.6"
-
Affected
Google
Search vendor "Google"
Android
Search vendor "Google" for product "Android"
2.1
Search vendor "Google" for product "Android" and version "2.1"
-
Affected
Google
Search vendor "Google"
Android
Search vendor "Google" for product "Android"
2.2
Search vendor "Google" for product "Android" and version "2.2"
rev1
Affected
Google
Search vendor "Google"
Android
Search vendor "Google" for product "Android"
2.2.1
Search vendor "Google" for product "Android" and version "2.2.1"
-
Affected