CVE-2014-7952

HIGH

Android - Arbitrary Code Execution via ADB Backup APK Injection

Title source: llm
STIX 2.1

Description

The backup mechanism in the adb tool in Android might allow attackers to inject additional applications (APKs) and execute arbitrary code by leveraging failure to filter application data streams.

References (6)

Core 6
Core References
Exploit, Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2015/Jul/46
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
http://packetstormsecurity.com/files/132645/ADB-Backup-APK-Injection.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/75705
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/535980/100/0/threaded

Scores

CVSS v3 7.8
EPSS 0.0040
EPSS Percentile 32.1%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-74
Status published
Products (1)
google/android
Published Jan 12, 2018
Tracked Since Feb 18, 2026