CVE-2017-13156
published 2017-12-06CVE-2017-13156: An elevation of privilege vulnerability in the Android system (art). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID…
PriorityP180high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
ITWEXPLOITVulnCheck KEVInitial access
Exploited in the wild
EPSS
20.09%
97.2th percentile
An elevation of privilege vulnerability in the Android system (art). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID A-64211847.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | android-platform-system-core | — | — |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| google_inc | android | — | — |
| google_inc | android | — | — |
| google_inc | android | — | — |
| google_inc | android | — | — |
| google_inc | android | — | — |
| google_inc | android | — | — |
| google_inc | android | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect APK files where a DEX file magic header is prepended before the ZIP/APK content — the file begins with a DEX header followed by valid APK (ZIP) data. ↗
- →Flag Android apps (APKs) that are signed exclusively with v1 signature scheme (no APK Signature Scheme v2 block present) as higher risk for Janus exploitation; v2-signed APKs are not vulnerable. ↗
- →Detect ANDROIDOS_JANUS.A: malware that embeds a small DEX payload in the APK header which decrypts and dynamically loads the actual malicious payload from assets at runtime. ↗
- →Monitor for Android apps that register a background service triggered on device boot and subsequently connect to a remote C&C server to download and install additional malware. ↗
- ·Only APKs signed with v1 signature scheme are vulnerable; APKs using APK Signature Scheme v2 (introduced in Android 7.0 Nougat) are protected because the signing block covers the full file from start to the signing block, detecting any prepended DEX. ↗
- ·Devices running Android 5.1.1 through 8.0 are affected; the Metasploit module requires a multi/handler to be started separately as the payload handler is disabled within the module. ↗
- ·Mixed (v1+v2) signing is common for compatibility; on devices that support v2, rollback protection enforces v2, but on older Android versions only v1 is checked, leaving them still vulnerable. ↗
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vulncheck7.8HIGH
vendor_debian7.8LOW
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Android
CVE-2017-13156: Android Security Bulletin 2017-12-01
CVE: CVE-2017-13156
Severity: HIGH
Type: EoP
Affected AOSP versions: 5
vendor_android·2017-12-01·CVSS 7.8
CVE-2017-13156 [HIGH] CVE-2017-13156: Android Security Bulletin 2017-12-01
CVE: CVE-2017-13156
Severity: HIGH
Type: EoP
Affected AOSP versions: 5
Android Security Bulletin 2017-12-01
CVE: CVE-2017-13156
Severity: HIGH
Type: EoP
Affected AOSP versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0
References: A-64211847
Debian
CVE-2017-13156: android-platform-system-core - An elevation of privilege vulnerability in the Android system (art). Product: An...
vendor_debian·2017·CVSS 7.8
CVE-2017-13156 [HIGH] CVE-2017-13156: android-platform-system-core - An elevation of privilege vulnerability in the Android system (art). Product: An...
An elevation of privilege vulnerability in the Android system (art). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID A-64211847.
Scope: local
bullseye: resolved
GHSA
GHSA-xvc2-w348-m54q: An elevation of privilege vulnerability in the Android system (art)
ghsa_unreviewed·2022-05-13
CVE-2017-13156 [HIGH] CWE-434 GHSA-xvc2-w348-m54q: An elevation of privilege vulnerability in the Android system (art)
An elevation of privilege vulnerability in the Android system (art). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID A-64211847.
VulnCheck
Google Android Unrestricted Upload of File with Dangerous Type
vulncheck·2017·CVSS 7.8
CVE-2017-13156 [HIGH] Google Android Unrestricted Upload of File with Dangerous Type
Google Android Unrestricted Upload of File with Dangerous Type
An elevation of privilege vulnerability in the Android system (art). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID A-64211847.
Affected: Google Android
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://news.drweb.com/show/?i=13108; https://news.drweb.com/show/review/?lng=en&i=13278; https://www.trendmicro.com/vinfo/us/security/news/cybercrime-and-digital-threats/agent-smith-malware-infecting-android-apps-devices-for-adware
Exploit PoC: https://vulncheck.com/xdb/f5b5819faf5d; https://vulncheck.com/xdb/c89fdeadf8fb; https://vulncheck.com/xdb/6f979f8191d
No detection rules found.
Exploit-DB
Android Janus - APK Signature Bypass (Metasploit)
exploitdb·2019-11-08·CVSS 7.8
CVE-2017-13156 [HIGH] Android Janus - APK Signature Bypass (Metasploit)
Android Janus - APK Signature Bypass (Metasploit)
---
##
# This module requires Metasploit: https://metasploit.com/download
# Current source: https://github.com/rapid7/metasploit-framework
##
require 'msf/core/payload/apk'
class MetasploitModule "Android Janus APK Signature bypass",
'Description' => %q{
This module exploits CVE-2017-13156 in Android to install a payload into another
application. The payload APK will have the same signature and can be installed
as an update, preserving the existing data.
The vulnerability was fixed in the 5th December 2017 security patch, and was
additionally fixed by the APK Signature scheme v2, so only APKs signed with
the v1 scheme are vulnerable.
Payload handler is disabled, and a multi/handler must be started first.
},
'Author' => [
'GuardSquare', #
Metasploit
Android Janus APK Signature bypass
metasploit·CVSS 7.8
CVE-2017-13156 [HIGH] Android Janus APK Signature bypass
Android Janus APK Signature bypass
This module exploits CVE-2017-13156 in Android to install a payload into another application. The payload APK will have the same signature and can be installed as an update, preserving the existing data. The vulnerability was fixed in the 5th December 2017 security patch, and was additionally fixed by the APK Signature scheme v2, so only APKs signed with the v1 scheme are vulnerable. Payload handler is disabled, and a multi/handler must be started first.
arXiv
Dissecting contact tracing apps in the Android platform
arxiv_fulltext·2021-05-21
Dissecting contact tracing apps in the Android platform
Dissecting contact tracing apps in the Android platform
[1]Vasileios Kouliaridis
[2]Georgios Kambourakis
[1]Efstratios Chatzoglou
[3]Dimitrios Geneiatakis
[4]Hua Wang
[1]Department of Information & Communication Systems Engineering, University of the Aegean, Greece
[2]European Commission, Joint Research Centre (JRC), 21027 Ispra (VA), Italy
[3]European Commission, Directorate-General for Informatics, 1000 Bruxelles/Brussel, Belgium
[4]Institute of Sustainable Industries and Liveable Cities, Victoria University, Melbourne, VIC 8001, Australia
This work is published in PLOS ONE, DOI: https://doi.org/10.1371/journal.pone.0251867.
Abstract: Contact tracing has historically been used to retard the spread of infectious diseases, but if it is exercised by hand in large-scale, it is known to b
arXiv
A Large-Scale Empirical Study on Industrial Fake Apps
arxiv_fulltext·2019-02-10
A Large-Scale Empirical Study on Industrial Fake Apps
A Large-Scale Empirical Study on Industrial
Fake Apps
Chongbin Tang1,
Sen Chen1,
Lingling Fan1,
Lihua Xu2,
Yang Liu3,
Zhushou Tang4,
Liang Dou1Chongbin Tang and Sen Chen are co-first authors. Lingling Fan and Liang Dou are the corresponding authors.Emails: [email protected], [email protected]
1East China Normal University, China
2New York University Shanghai, China
3Nanyang Technological University, Singapore
4Pwnzen Infotech Inc., China
2pt
## Abstract
While there have been various studies towards Android apps and their development,
there is limited discussion of the broader class of apps that fall in the fake area.
Fake apps and their development are distinct from official apps and belong to the mobile underground industry.
Due to the lack of knowledge of the mobile
Trendmicro
Janus Android Vulnerability Allows App Modifications
blogs_trendmicro·2017-12-26·CVSS 7.8
[HIGH] Janus Android Vulnerability Allows App Modifications
Mobile
## Janus Android Vulnerability Allows App Modifications
Android’s regular security update for December 2017 included a fix for a serious vulnerability that could allow attackers to modify installed apps without affecting their signature. This vulnerability affects approximately 74% of all Android devices.
By: Veo Zhang Dec 26, 2017 Read time: ( words)
Save to Folio
Android’s regular security update for December 2017 included a fix for a serious vulnerability that could allow attackers to modify installed apps without affecting their signature. This would allow an attacker to gain access to the affected device (indirectly). First found by researchers in July , this vulnerability (designated as CVE-2017-13156, and also called the Janus vulnerability) affects versions of Android f
Trendmicro
Janus Android Vulnerability Allows App Modifications
blogs_trendmicro·2017-12-26·CVSS 7.8
[HIGH] Janus Android Vulnerability Allows App Modifications
Dispositivos móviles
## Janus Android Vulnerability Allows App Modifications
Android’s regular security update for December 2017 included a fix for a serious vulnerability that could allow attackers to modify installed apps without affecting their signature. This vulnerability affects approximately 74% of all Android devices.
By: Veo Zhang Dec 26, 2017 Read time: ( words)
Save to Folio
Android’s regular security update for December 2017 included a fix for a serious vulnerability that could allow attackers to modify installed apps without affecting their signature. This would allow an attacker to gain access to the affected device (indirectly). First found by researchers in July , this vulnerability (designated as CVE-2017-13156, and also called the Janus vulnerability) affects version
Trendmicro
Janus Android Vulnerability Allows App Modifications
blogs_trendmicro·2017-12-26·CVSS 7.8
[HIGH] Janus Android Vulnerability Allows App Modifications
Mobilgeräte
## Janus Android Vulnerability Allows App Modifications
Android’s regular security update for December 2017 included a fix for a serious vulnerability that could allow attackers to modify installed apps without affecting their signature. This vulnerability affects approximately 74% of all Android devices.
By: Veo Zhang Dec 26, 2017 Read time: ( words)
Save to Folio
Android’s regular security update for December 2017 included a fix for a serious vulnerability that could allow attackers to modify installed apps without affecting their signature. This would allow an attacker to gain access to the affected device (indirectly). First found by researchers in July , this vulnerability (designated as CVE-2017-13156, and also called the Janus vulnerability) affects versions of Andr
Trendmicro
Janus Android Vulnerability Allows App Modifications
blogs_trendmicro·2017-12-26·CVSS 7.8
[HIGH] Janus Android Vulnerability Allows App Modifications
Mobile
## Janus Android Vulnerability Allows App Modifications
Android’s regular security update for December 2017 included a fix for a serious vulnerability that could allow attackers to modify installed apps without affecting their signature. This vulnerability affects approximately 74% of all Android devices.
By: Veo Zhang 2017/12/26 Read time: ( words)
Save to Folio
Android’s regular security update for December 2017 included a fix for a serious vulnerability that could allow attackers to modify installed apps without affecting their signature. This would allow an attacker to gain access to the affected device (indirectly). First found by researchers in July , this vulnerability (designated as CVE-2017-13156, and also called the Janus vulnerability) affects versions of Android fro
Trendmicro
Janus Android Vulnerability Allows App Modifications
blogs_trendmicro·2017-12-26·CVSS 7.8
[HIGH] Janus Android Vulnerability Allows App Modifications
Mobile
# Janus Android Vulnerability Allows App Modifications
Android’s regular security update for December 2017 included a fix for a serious vulnerability that could allow attackers to modify installed apps without affecting their signature. This vulnerability affects approximately 74% of all Android devices.
By: Veo Zhang
2017/12/26
Read time: ( words)
Save to Folio
Android’s regular security update for December 2017 included a fix for a serious vulnerability that could allow attackers to modify installed apps without affecting their signature. This would allow an attacker to gain access to the affected device (indirectly). First found by researchers in July, this vulnerability (designated as CVE-2017-13156, and also called the Janus vulnerability) affects versions of Android from
Bugzilla
Firefox Focus for Android v6.1.1 allow attackers to modify apps without affecting their signature
bugzilla·2018-09-10·CVSS 7.8
[HIGH] Firefox Focus for Android v6.1.1 allow attackers to modify apps without affecting their signature
Firefox Focus for Android v6.1.1 allow attackers to modify apps without affecting their signature
Created attachment 9007689
fiefox Focus.jpg
User Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_13_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/68.0.3440.106 Safari/537.36
Steps to reproduce:
Checking the Firefox for Android App`s signature information, I notice that Firefox Focus for Android v6.1.1 is using signature scheme version 1. App`s signature information screenshots attached.
Actual results:
It is a serious vulnerability that could allow attackers to modify installed apps without affecting their signature. This vulnerability (designated as CVE-2017-13156, and also called the Janus vulnerability) affects versions of Android from 5.1.1 to 8.0
Expected results:
For compat
Bugzilla
Firefox for Android App allow attackers to modify apps without affecting their signature.
bugzilla·2018-09-10·CVSS 7.8
[HIGH] Firefox for Android App allow attackers to modify apps without affecting their signature.
Firefox for Android App allow attackers to modify apps without affecting their signature.
Created attachment 9007684
firefox62.jpg
User Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_13_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/68.0.3440.106 Safari/537.36
Steps to reproduce:
Checking the Firefox for Android App`s signature information, I notice that it is using signature scheme version 1. App`s signature information screenshots attached.
Actual results:
It is a serious vulnerability that could allow attackers to modify installed apps without affecting their signature. This vulnerability (designated as CVE-2017-13156, and also called the Janus vulnerability) affects versions of Android from 5.1.1 to 8.0
Expected results:
For compatibility reasons, developer could use a mi
OWASP
Mastg Test 0224
owasp·CVSS 7.8
CVE-2017-13156 [HIGH] Mastg Test 0224
## Overview
Not using newer APK signing schemes means that the app lacks the enhanced security provided by more robust, updated mechanisms.
This test checks if the outdated v1 signature scheme is enabled. The v1 scheme is vulnerable to certain attacks, such as the "Janus" vulnerability ([CVE-2017-13156](https://nvd.nist.gov/vuln/detail/CVE-2017-13156)), because it does not cover all parts of the APK file, allowing malicious actors to potentially **modify parts of the APK without invalidating the signature**. Relying solely on v1 signing therefore increases the risk of tampering and compromises app security.
To learn more about APK Signing Schemes, see ["Signing Process"](../../../Document/0x05a-Platform-Overview.md#signing-process).
## Steps
1. Obtain the `minSdkVersion` attribute fro
OWASP
Android Platform Overview
owasp
Android Platform Overview
# Android Platform Overview
This chapter introduces the Android platform from an architecture point of view. The following five key areas are discussed:
1. Android architecture
2. Android security: defense-in-depth approach
3. Android application structure
4. Android application publishing
5. Android application attack surface
Visit the official [Android developer documentation website](https://developer.android.com/index.html "Android Developer Guide") for more details about the Android platform.
## Android Architecture
[Android](https://en.wikipedia.org/wiki/Android_(operating_system) "Android (Operating System)") is a Linux-based open source platform developed by the [Open Handset Alliance](https://www.openhandsetalliance.com/) (a consortium lead by Google), which serves as a mobil
OWASP
Mastg Test 0038
owasp·CVSS 7.8
[HIGH] Mastg Test 0038
## Overview
Ensure that the release builds are properly signed to safeguard their integrity and protect them from tampering. Android has evolved its signing schemes over time to enhance security, with newer versions offering more robust mechanisms.
- **Android 7.0 (API level 24) and above**: Use at least the **v2 signature scheme**, which signs the APK as a whole, providing stronger protection compared to the older v1 (JAR) signing method.
- **Android 9 (API level 28) and above**: It's recommended to use both the **v2 and v3 signature schemes**. The v3 scheme supports **key rotation**, enabling developers to replace keys in the event of a compromise without invalidating old signatures.
- **Android 11 (API level 30) and above**: Optionally include the **v4 signature scheme** to enable fas
http://packetstormsecurity.com/files/155189/Android-Janus-APK-Signature-Bypass.htmlhttp://www.securityfocus.com/bid/102109https://source.android.com/security/bulletin/2017-12-01http://packetstormsecurity.com/files/155189/Android-Janus-APK-Signature-Bypass.htmlhttp://www.securityfocus.com/bid/102109https://source.android.com/security/bulletin/2017-12-01
2017-12-06
Published
Exploited in the wild