Vulnerabilities > CVE-2017-13209 - Missing Authorization vulnerability in Google Android 8.0/8.1

047910
CVSS 7.2 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
local
low complexity
google
CWE-862
exploit available

Summary

In the ServiceManager::add function in the hardware service manager, there is an insecure permissions check based on the PID of the caller which could allow an application or service to replace a HAL service with its own service. This could lead to a local elevation of privilege enabling code execution as a privileged process with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 8.0, 8.1. Android ID: A-68217907.

Vulnerable Configurations

Part Description Count
OS
Google
2

Common Weakness Enumeration (CWE)

Exploit-Db

descriptionAndroid - Hardware Service Manager Arbitrary Service Replacement due to getpidcon. CVE-2017-13209. Dos exploit for Android platform
fileexploits/android/dos/43513.txt
idEDB-ID:43513
last seen2018-01-24
modified2018-01-11
platformandroid
port
published2018-01-11
reporterExploit-DB
sourcehttps://www.exploit-db.com/download/43513/
titleAndroid - Hardware Service Manager Arbitrary Service Replacement due to getpidcon
typedos