LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2011-1823: Android OS Privilege Escalation Vulnerability

RBRecent Breaches Vulnerability Intelligence·Sep 8, 2022
CVSS 7.8 · High⚠ Actively exploited (CISA KEV)
7.8
CVSS score
High
Severity
Active
CISA KEV
No
Ransomware use
Sep 29, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2011-1823 to its Known Exploited Vulnerabilities catalog on Sep 8, 2022, with a federal patch deadline of Sep 29, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

The vold volume manager daemon on Android 3.0 and 2.x before 2.3.4 trusts messages that are received from a PF_NETLINK socket, which allows local users to execute arbitrary code and gain root privileges via a negative index that bypasses a maximum-only signed integer check in the DirectVolume::handlePartitionAdded method, which triggers memory corruption, as demonstrated by Gingerbreak.

CVE-2011-1823 is a privilege-escalation flaw in the Android OS volume manager daemon (vold). An attacker who can already run code on a device can abuse trusted netlink messages to execute code with root privileges. It matters because root access undermines app sandboxing, device integrity, and any data or credentials stored on the handset. The issue is associated with the GingerBreak and Exploit.AndroidOS.Lotoor families; confirm exact impact and fixed builds against the vendor advisory.

How it works

The weakness is classified as CWE-189 (Numeric Errors). The vold daemon trusts messages received on a PF_NETLINK socket. By crafting those messages, an attacker can trigger incorrect handling that leads to code execution in the privileged context of vold, elevating to root. Public detail beyond this description is limited; do not assume specific message formats, offsets, or payload construction without verifying against the original research and vendor notes. The practical result is local privilege escalation from an unprivileged process to full device control.

Am I affected? How to find it in your systems

This affects Android OS installations that still run a vulnerable vold implementation. Typical environments include older handsets, tablets, embedded Android devices, and any corporate fleet that has not been updated for many years.

How to remediate

Patch first. Apply the platform updates supplied by the device manufacturer or carrier exactly as directed in the vendor advisory and the CISA-required action (“Apply updates per vendor instructions”).

If you can't patch immediately

Compensating controls reduce but do not eliminate risk on an unpatched Android device.

If your data may have been exposed

Actively exploited privilege-escalation vulnerabilities can lead to full device compromise and subsequent data theft. If you suspect exposure, follow your incident-response process: isolate the device, preserve evidence, rotate credentials that may have been accessible from it, and review access logs for misuse. You can also run a free exposure scan of your email addresses to check whether they appear in known breach data sets.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedAndroid · Android OS
WeaknessCWE-190
CVSS base score7.8 (High)
CVSS vectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
PublishedJun 9, 2011
Added to CISA KEVSep 8, 2022
Federal patch deadlineSep 29, 2022
Known ransomware useNot documented
Check if your data is exposed →

References

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities