Privilege escalation in AirWatch Launcher for Android - CVE-2017-4932

 

Privilege escalation in AirWatch Launcher for Android - CVE-2017-4932

Published: November 10, 2017


Vulnerability identifier: #VU9175
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-4932
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to gain elevated privileges on the target system.

The weakness exists due to a flaw in the AirWatch Launcher for Android. A local attacker can gain privileged access to the system and perform arbitrary actions.


Affected software

AirWatch Launcher for Android
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
Desktop Applications Module
openSUSE Leap
mutter
mutter-debuginfo
mutter-devel
mutter-debugsource
mutter-lang

How to mitigate CVE-2017-4932

Update to version 3.2.2.

mutter - update to 45.3-150600.5.9.1
mutter-debuginfo - update to 45.3-150600.5.9.1
mutter-devel - update to 45.3-150600.5.9.1
mutter-debugsource - update to 45.3-150600.5.9.1
mutter-lang - update to 45.3-150600.5.9.1

External References

Related Security Bulletins