Privilege escalation in SHIELD TV - CVE-2017-6279

 

Privilege escalation in SHIELD TV - CVE-2017-6279

Published: February 21, 2018


Vulnerability identifier: #VU10669
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-6279
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to gain elevated privileges on the target system.

The weakness exists due to a flaw in OMX.Nvidia.aac.decoder in NVIDIA Tegra OpenMax Component. A local attacker can disable the dead code to avoid malicious software, instantiate the vulnerable component and cause service to crash or gain elevated privileges.

Affected software

SHIELD TV

How to mitigate CVE-2017-6279

Update to version 6.3.


External References

Related Security Bulletins