10
CVSSv2

CVE-2017-13281

Published: 04/04/2018 Updated: 09/05/2018
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

In avrc_pars_browsing_cmd of avrc_pars_tg.cc, there is a possible stack buffer overflow due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 8.0, 8.1. Android ID: A-71603262.

Vulnerable Product Search on Vulmon Subscribe to Product

google android 8.0

google android 8.1

Github Repositories

Vulnerability PoCs of Android Bluetoodh avrcp_CVE-2017-13281c is the CVE-2017-13281 poc code $ mv avrcp_CVE-2017-13281c blue-537/profiles/audio/avrcpc just replace blue-537/profiles/audio/avrcpc with poc, and compile the source code on ubuntu 1604, run bluetoothd manually, and paired my pixel xl with my laptop Once paired, the attack payload will be sent automatical