CVE-2017-0752
published 2017-09-08CVE-2017-0752: A elevation of privilege vulnerability in the Android framework (windowmanager). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1…
PriorityP434high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
EPSS
0.43%
35.1th percentile
A elevation of privilege vulnerability in the Android framework (windowmanager). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-62196835.
Affected
39 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | android-framework-23 | — | — |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian7.8LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7qrw-qmwr-7342: A elevation of privilege vulnerability in the Android framework (windowmanager)
ghsa_unreviewed·2022-05-13
CVE-2017-0752 [HIGH] CWE-732 GHSA-7qrw-qmwr-7342: A elevation of privilege vulnerability in the Android framework (windowmanager)
A elevation of privilege vulnerability in the Android framework (windowmanager). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-62196835.
OSV
CVE-2017-0752: A elevation of privilege vulnerability in the Android framework (windowmanager)
osv·2017-09-08·CVSS 7.8
CVE-2017-0752 [HIGH] CVE-2017-0752: A elevation of privilege vulnerability in the Android framework (windowmanager)
A elevation of privilege vulnerability in the Android framework (windowmanager). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-62196835.
Android
CVE-2017-0752: Android Security Bulletin 2017-09-01
CVE: CVE-2017-0752
Severity: HIGH
Type: EoP
Affected AOSP versions: 4
vendor_android·2017-09-01·CVSS 7.8
CVE-2017-0752 [HIGH] CVE-2017-0752: Android Security Bulletin 2017-09-01
CVE: CVE-2017-0752
Severity: HIGH
Type: EoP
Affected AOSP versions: 4
Android Security Bulletin 2017-09-01
CVE: CVE-2017-0752
Severity: HIGH
Type: EoP
Affected AOSP versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2
References: A-62196835
[2]
Debian
CVE-2017-0752: android-framework-23 - A elevation of privilege vulnerability in the Android framework (windowmanager)....
vendor_debian·2017·CVSS 7.8
CVE-2017-0752 [HIGH] CVE-2017-0752: android-framework-23 - A elevation of privilege vulnerability in the Android framework (windowmanager)....
A elevation of privilege vulnerability in the Android framework (windowmanager). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-62196835.
Scope: local
bullseye: open
sid: open
No detection rules found.
No public exploits indexed.
Trendmicro
Toast Overlay Weaponized to Install Android Malware
blogs_trendmicro·2017-11-09·CVSS 7.8
[HIGH] Toast Overlay Weaponized to Install Android Malware
Mobile
## Toast Overlay Weaponized to Install Android Malware
A new Android malware can install other malware on affected devices via the Toast Overlay attack: TOASTAMIGO. The malicious apps abuse Android’s Accessibility features, enabling them to have ad-clicking, app-installing and other capabilities.
By: Lorin Wu Nov 09, 2017 Read time: ( words)
Save to Folio
Updated as of November 16, 2017, 6:30PM PDT to clarify the number of installs in one of the malicious apps.
We uncovered new Android malware that can surreptitiously install other malware on the affected device via the Toast Overlay attack : TOASTAMIGO, detected by Trend Micro as ANDROIDOS_TOASTAMIGO. The malicious apps, one of which had installs between 100,000 and 500,000 as of November 6, 2017, abuses Android’s Accessibili
Trendmicro
Toast Overlay Weaponized to Install Android Malware
blogs_trendmicro·2017-11-09·CVSS 7.8
[HIGH] Toast Overlay Weaponized to Install Android Malware
Mobile
# Toast Overlay Weaponized to Install Android Malware
A new Android malware can install other malware on affected devices via the Toast Overlay attack: TOASTAMIGO. The malicious apps abuse Android’s Accessibility features, enabling them to have ad-clicking, app-installing and other capabilities.
By: Lorin Wu
2017/11/09
Read time: ( words)
Save to Folio
Updated as of November 16, 2017, 6:30PM PDT to clarify the number of installs in one of the malicious apps.
We uncovered new Android malware that can surreptitiously install other malware on the affected device via the Toast Overlay attack: TOASTAMIGO, detected by Trend Micro as ANDROIDOS_TOASTAMIGO. The malicious apps, one of which had installs between 100,000 and 500,000 as of November 6, 2017, abuses Android’s Accessibility
Trendmicro
Toast Overlay Weaponized to Install Android Malware
blogs_trendmicro·2017-11-09·CVSS 7.8
[HIGH] Toast Overlay Weaponized to Install Android Malware
Dispositivos móviles
## Toast Overlay Weaponized to Install Android Malware
A new Android malware can install other malware on affected devices via the Toast Overlay attack: TOASTAMIGO. The malicious apps abuse Android’s Accessibility features, enabling them to have ad-clicking, app-installing and other capabilities.
By: Lorin Wu Nov 09, 2017 Read time: ( words)
Save to Folio
Updated as of November 16, 2017, 6:30PM PDT to clarify the number of installs in one of the malicious apps.
We uncovered new Android malware that can surreptitiously install other malware on the affected device via the Toast Overlay attack : TOASTAMIGO, detected by Trend Micro as ANDROIDOS_TOASTAMIGO. The malicious apps, one of which had installs between 100,000 and 500,000 as of November 6, 2017, abuses Android
Trendmicro
Toast Overlay Weaponized to Install Android Malware
blogs_trendmicro·2017-11-09·CVSS 7.8
[HIGH] Toast Overlay Weaponized to Install Android Malware
Mobile
## Toast Overlay Weaponized to Install Android Malware
A new Android malware can install other malware on affected devices via the Toast Overlay attack: TOASTAMIGO. The malicious apps abuse Android’s Accessibility features, enabling them to have ad-clicking, app-installing and other capabilities.
By: Lorin Wu 2017/11/09 Read time: ( words)
Save to Folio
Updated as of November 16, 2017, 6:30PM PDT to clarify the number of installs in one of the malicious apps.
We uncovered new Android malware that can surreptitiously install other malware on the affected device via the Toast Overlay attack : TOASTAMIGO, detected by Trend Micro as ANDROIDOS_TOASTAMIGO. The malicious apps, one of which had installs between 100,000 and 500,000 as of November 6, 2017, abuses Android’s Accessibility
Trendmicro
Toast Overlay Weaponized to Install Android Malware
blogs_trendmicro·2017-11-09·CVSS 7.8
[HIGH] Toast Overlay Weaponized to Install Android Malware
Mobilgeräte
## Toast Overlay Weaponized to Install Android Malware
A new Android malware can install other malware on affected devices via the Toast Overlay attack: TOASTAMIGO. The malicious apps abuse Android’s Accessibility features, enabling them to have ad-clicking, app-installing and other capabilities.
By: Lorin Wu Nov 09, 2017 Read time: ( words)
Save to Folio
Updated as of November 16, 2017, 6:30PM PDT to clarify the number of installs in one of the malicious apps.
We uncovered new Android malware that can surreptitiously install other malware on the affected device via the Toast Overlay attack : TOASTAMIGO, detected by Trend Micro as ANDROIDOS_TOASTAMIGO. The malicious apps, one of which had installs between 100,000 and 500,000 as of November 6, 2017, abuses Android’s Access
Unit42
Android Toast Overlay Attack: “Cloak and Dagger” with No Permissions
blogs_unit42·2017-09-07
Android Toast Overlay Attack: “Cloak and Dagger” with No Permissions
Palo Alto Networks Unit 42 researchers have uncovered a high severity vulnerability in the Android overlay system, which allows a new Android overlay attack by using the “Toast type” overlay. All Android devices with OS version < 8.0 are affected by this vulnerability and patches are available as part of the September 2017 Android Security Bulletin. Android 8.0 was just released and is unaffected by this vulnerability. Because Android 8.0 is recent, this vulnerability affects nearly all Android devices currently in the market (see Table 1) and users should apply updates as soon as possible.
Overlay attacks permit an attacker to draw on top of other windows and apps running on the affected device. To launch such an attack, malware normally needs to request the “draw on top” permission. How
Unit42
Android Toast Overlay Attack: “Cloak and Dagger” with No Permissions
blogs_unit42·2017-09-07
Android Toast Overlay Attack: “Cloak and Dagger” with No Permissions
## Android Toast Overlay Attack: “Cloak and Dagger” with No Permissions
Cong Zheng
Wenjun Hu
Xiao Zhang
Zhi Xu
Published: September 7, 2017
Ransomware
Threat Research
Vulnerabilities
Android
Cloak and Dagger
Palo Alto Networks Unit 42 researchers have uncovered a high severity vulnerability in the Android overlay system, which allows a new Android overlay attack by using the “Toast type” overlay. All Android devices with OS version < 8.0 are affected by this vulnerability and patches are available as part of the September 2017 Android Security Bulletin . Android 8.0 was just released and is unaffected by this vulnerability. Because Android 8.0 is recent, this vulnerability affects nearly all Android devices currently in the market ( see Table 1 ) and users should apply updates
2017-09-08
Published