10
CVSSv2

CVE-2017-0807

Published: 04/10/2017 Updated: 03/10/2019
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

An elevation of privilege vulnerability in the Android framework (ui framework). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-35056974.

Vulnerable Product Search on Vulmon Subscribe to Product

google android 6.0.1

google android 7.1.1

google android 4.4.4

google android 5.0.2

google android 5.1.1

google android 7.1.2

google android 6.0

google android 7.0

Github Repositories

Proof of concept of CVE-2017-0807

Proof of concept of CVE-2017-0807 This is a demo application with deliberately sloppy interface for the CVE-2017-0807 reported by Efthimios Alepis and Constantinos Patsakis The vulnerability illustrates that due to security issues in every Android version up to Nougat, an unprivileged user can overlay almost every Android interface and trick the user into getting his input In