CVE-2014-7920

CRITICAL

Android 2.2-5.x - Privilege Escalation in mediaserver

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2014-7920. PoCs published by laginimaineb, Vinc3nt4H.

AI-analyzed exploit summary This repository contains a functional exploit for CVE-2014-7920 and CVE-2014-7921, targeting a code execution vulnerability in the mediaserver component of Android up to version 5.1. The exploit leverages memory manipulation and function pointer overwrites to achieve remote code execution.

Description

mediaserver in Android 2.2 through 5.x before 5.1 allows attackers to gain privileges. NOTE: This is a different vulnerability than CVE-2014-7921.

Exploits (2)

nomisec WORKING POC 76 stars
by laginimaineb · poc
https://github.com/laginimaineb/cve-2014-7920-7921

This repository contains a functional exploit for CVE-2014-7920 and CVE-2014-7921, targeting a code execution vulnerability in the mediaserver component of Android up to version 5.1. The exploit leverages memory manipulation and function pointer overwrites to achieve remote code execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Complex
Reliability
Reliable
Target: Android mediaserver (up to Android 5.1)
No auth needed
Prerequisites: Access to the target device's mediaserver component · Android version up to 5.1
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 6 stars
by Vinc3nt4H · poc
https://github.com/Vinc3nt4H/cve-2014-7920-7921_update

This repository contains a functional exploit for CVE-2014-7920 and CVE-2014-7921, targeting the mediaserver component in Android versions up to 5.1. The exploit leverages memory corruption to achieve remote code execution by manipulating function pointers and executing arbitrary commands via the 'system' function.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Complex
Reliability
Reliable
Target: Android mediaserver (up to version 5.1)
No auth needed
Prerequisites: Access to the target device's mediaserver component · Android version up to 5.1
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2

Scores

CVSS v3 9.8
EPSS 0.0962
EPSS Percentile 93.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-264
Status published
Products (39)
google/android 2.2 (2 CPE variants)
google/android 2.2.1
google/android 2.2.2
google/android 2.2.3
google/android 2.3 (2 CPE variants)
google/android 2.3.1
google/android 2.3.2
google/android 2.3.3
google/android 2.3.4
google/android 2.3.5
... and 29 more
Published Apr 13, 2017
Tracked Since Feb 18, 2026