CVE-2017-0601
MEDIUMAndroid 7.0-7.1.2 - Elevation of Privilege via Bluetooth File Acceptance
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-0601. PoCs published by heeeeen.
AI-analyzed exploit summary This PoC exploits CVE-2017-0601, a vulnerability in Android's Bluetooth component where an attacker can bypass user confirmation for incoming files by sending a broadcast intent to manipulate the file acceptance status. The code iterates through possible URIs to guess and accept incoming Bluetooth shares without user interaction.
Description
An Elevation of Privilege vulnerability in Bluetooth could potentially enable a local malicious application to accept harmful files shared via bluetooth without user permission. This issue is rated as Moderate due to local bypass of user interaction requirements. Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-35258579.
Exploits (1)
This PoC exploits CVE-2017-0601, a vulnerability in Android's Bluetooth component where an attacker can bypass user confirmation for incoming files by sending a broadcast intent to manipulate the file acceptance status. The code iterates through possible URIs to guess and accept incoming Bluetooth shares without user interaction.
References (2)
Scores
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N