#VU10669 Privilege escalation in SHIELD TV - CVE-2017-6279 

 

#VU10669 Privilege escalation in SHIELD TV - CVE-2017-6279

Published: February 21, 2018


Vulnerability identifier: #VU10669
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/U:Clear
CVE-ID: CVE-2017-6279
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability: No public exploit available
Vulnerable software:
SHIELD TV
Software vendor:
nVidia

Description

The vulnerability allows a local attacker to gain elevated privileges on the target system.

The weakness exists due to a flaw in OMX.Nvidia.aac.decoder in NVIDIA Tegra OpenMax Component. A local attacker can disable the dead code to avoid malicious software, instantiate the vulnerable component and cause service to crash or gain elevated privileges.

Remediation

Update to version 6.3.

External links