CVE-2017-0807

CRITICAL

Android <7.1.2 - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2017-0807. PoCs published by kpatsakis.

AI-analyzed exploit summary This repository contains a functional proof-of-concept for CVE-2017-0807, demonstrating how an unprivileged Android app can overlay system interfaces to trick users into granting device admin privileges. The exploit leverages UI overlay techniques without requiring dangerous permissions like SYSTEM ALERT WINDOW.

Description

An elevation of privilege vulnerability in the Android framework (ui framework). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-35056974.

Exploits (1)

nomisec WORKING POC 1 stars
by kpatsakis · poc
https://github.com/kpatsakis/PoC_CVE-2017-0807

This repository contains a functional proof-of-concept for CVE-2017-0807, demonstrating how an unprivileged Android app can overlay system interfaces to trick users into granting device admin privileges. The exploit leverages UI overlay techniques without requiring dangerous permissions like SYSTEM ALERT WINDOW.

Classification
Working Poc 95%
Attack Type
Other
Complexity
Moderate
Reliability
Reliable
Target: Android (up to Nougat)
No auth needed
Prerequisites: Android device running up to Nougat · User interaction to trigger overlay
MITRE ATT&CK
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/101190
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/102131
Vendor Advisory x_refsource_confirm
https://source.android.com/security/bulletin/2017-12-01

Scores

CVSS v3 9.8
EPSS 0.0185
EPSS Percentile 76.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

Status published
Products (14)
google/android 4.4.4
google/android 5.0.2
google/android 5.1.1
google/android 6.0
google/android 6.0.1
google/android 7.0
google/android 7.1.1
google/android 7.1.2
Google Inc./Android 5.1.1
Google Inc./Android 6.0
... and 4 more
Published Oct 04, 2017
Tracked Since Feb 18, 2026