CVE-2017-11013
HIGHAndroid for MSM - Buffer Overflow in UnpackCore Function
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-11013. PoCs published by ScottyBauer.
AI-analyzed exploit summary This is a functional proof-of-concept exploit for CVE-2017-11013, which targets a vulnerability in Android's WiFi stack. The code sets up a rogue access point to trigger the vulnerability, likely leading to remote code execution or denial of service.
Description
In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, countOffset (in function UnpackCore) is increased for each loop, while there is no boundary check against "pIe->arraybound".
Exploits (1)
This is a functional proof-of-concept exploit for CVE-2017-11013, which targets a vulnerability in Android's WiFi stack. The code sets up a rogue access point to trigger the vulnerability, likely leading to remote code execution or denial of service.
References (2)
Scores
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H