On Audi A7 MMI 2014 vehicles, the Bluetooth stack in Audi A7 MMI Multiplayer with version (N+R_CN_AU_P0395) mishandles %x and %s format string specifiers in a device name. This may lead to memory content leaks and potentially crash the services.
The product uses a function that accepts a format string as an argument, but the format string originates from an external source.
Link | Tags |
---|---|
https://www.youtube.com/watch?v=BQUVgAdhwQs | third party advisory exploit |
https://twitter.com/Kevin2600/status/1316380576593571840 | third party advisory |
https://tiger-team-1337.blogspot.com/2020/10/audi-a7-2014-mmi-mishandles-format.html | third party advisory exploit |