CVE-2017-3748: Google Android

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

On Lenovo VIBE mobile phones, improper access controls on the nac_server component can be abused in conjunction with CVE-2017-3749 and CVE-2017-3750 to elevate privileges to the root user (commonly known as 'rooting' or "jail breaking" a device).

Affected products

  • Google Android: up to and including 5.1.1

Published 2017-06-29. Last modified 2026-06-17.