CVE-2017-13266
CRITICALAndroid 5.1.1-8.1 - Remote Code Execution via Missing Bounds Check in avrc_pars_vendor_cmd
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-13266. PoCs published by codecat007.
AI-analyzed exploit summary This repository contains a functional proof-of-concept exploit for CVE-2017-13266, targeting a Bluetooth stack vulnerability in Android's Bluedroid. The exploit crafts malicious AVRCP packets to trigger a buffer overflow, potentially leading to remote code execution.
Description
In avrc_pars_vendor_cmd of avrc_pars_tg.cc, there is a possible stack corruption due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-69478941.
Exploits (1)
This repository contains a functional proof-of-concept exploit for CVE-2017-13266, targeting a Bluetooth stack vulnerability in Android's Bluedroid. The exploit crafts malicious AVRCP packets to trigger a buffer overflow, potentially leading to remote code execution.
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H