CVE-2017-4932
VMware AirWatch Launcher for Android prior to 3.2.2 contains a vulnerability that could allow an escalation of privilege from the launcher UI context menu to native UI functionality and privilege.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.40%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
VMware AirWatch Launcher for Android prior to 3.2.2 contains a vulnerability that could allow an escalation of privilege from the launcher UI context menu to native UI functionality and privilege. Successful exploitation of this issue could result in an escalation of privilege.
- CVSS 3.0
- 7.8 HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.40% probability · 33th percentile
- CISA KEV
- Not listed
- Affected
- vmware/airwatch launcher
- Source
- security@vmware.com
References
- http://www.securityfocus.com/bid/101771Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039750Third Party Advisory, VDB Entry
- https://www.vmware.com/us/security/advisories/VMSA-2017-0016.htmlPatch, Vendor Advisory
- http://www.securityfocus.com/bid/101771Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039750Third Party Advisory, VDB Entry
- https://www.vmware.com/us/security/advisories/VMSA-2017-0016.htmlPatch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.