9.3
CVSSv2

CVE-2015-6606

Published: 06/10/2015 Updated: 07/10/2015
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

The Secure Element Evaluation Kit (aka SEEK or SmartCard API) plugin in Android prior to 5.1.1 LMY48T allows malicious users to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 22301786.

Vulnerable Product Search on Vulmon Subscribe to Product

google android

Github Repositories

Simple Exploit for Verification of CVE-2015-6606

Simple Exploit for Verification of CVE-2015-6606 This is a simple exploit to verify a code injection vulnerability that exists in the SEEK smartcard service versions 310 and below (CVE-2015-6606, Google internal bug# ANDROID-22301786) The vulnerability allows specially crafted Android application packages to inject arbitrary code into the execution context of the smartcard s