7.8
CVSSv3

CVE-2017-13236

Published: 12/02/2018 Updated: 03/10/2019
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 465
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

In the KeyStore service, there is a permissions bypass that allows access to protected resources. This could lead to local escalation of privilege with system execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 8.0, 8.1. Android ID: A-68217699.

Vulnerable Product Search on Vulmon Subscribe to Product

google android 8.1

google android 8.0

Exploits

The keystore binder service ("androidsecurityIKeystoreService") allows users to issue several commands related to key management, including adding, removing, exporting and generating cryptographic keys The service is accessible to many SELinux contexts, including application contexts, but also unprivileged daemons such as "mediacodec" Binder ...