Improper Neutralization of Special Elements in Output Used by a Downstream Component in Google Android - CVE-2014-7952

 

Improper Neutralization of Special Elements in Output Used by a Downstream Component in Google Android - CVE-2014-7952

Published: January 12, 2018 / Updated: August 8, 2020


Vulnerability identifier: #VU37671
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2014-7952
CWE-ID: CWE-74
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local authenticated user to execute arbitrary code.

The backup mechanism in the adb tool in Android might allow attackers to inject additional applications (APKs) and execute arbitrary code by leveraging failure to filter application data streams.


Affected software

Google Android

How to mitigate CVE-2014-7952

Install update from vendor's website.


External References

Related Security Bulletins