CVE-2017-13315
HIGH EXPLOITEDAndroid - Elevation of Privileges via DcParamObject Parcel Size Mismatch
Title source: llmExploitation Summary
CVE-2017-13315 has been observed exploited in the wild (reported by VulnCheck KEV).
Description
In writeToParcel and createFromParcel of DcParamObject.java, there is a permission bypass due to a write size mismatch. This could lead to an elevation of privileges where the user can start an activity with system privileges, with no additional execution privileges needed. User interaction is not needed for exploitation.
References (1)
Core 1
Core References
Patch, Vendor Advisory
https://source.android.com/security/bulletin/2018-05-01
Scores
CVSS v3
7.8
EPSS
0.0010
EPSS Percentile
0.9%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
VulnCheck KEV
2019-04-12
CWE
CWE-131
Status
published
Products (7)
google/android
6.0
google/android
6.0.1
google/android
7.0
google/android
7.1.1
google/android
7.1.2
google/android
8.0
google/android
8.1
Published
Nov 19, 2024
Tracked Since
Feb 18, 2026