cbcvebase.
CVE-2017-13156
published 2017-12-06

CVE-2017-13156: An elevation of privilege vulnerability in the Android system (art). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID…

PriorityP180high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
ITWEXPLOITVulnCheck KEVInitial access
Exploited in the wild
EPSS
20.09%
97.2th percentile
An elevation of privilege vulnerability in the Android system (art). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID A-64211847.

Affected

16 ranges
VendorProductVersion rangeFixed in
debianandroid-platform-system-core
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
google_incandroid
google_incandroid
google_incandroid
google_incandroid
google_incandroid
google_incandroid
google_incandroid

Detection & IOCsextracted from sources · hover to see the quote

hasha28a10823a9cc7d7ebc1f169c544f2b14afc8b756087b5f2c3a50c088089f07d
othercom.fleeeishei.erabladmounsem
  • Detect APK files where a DEX file magic header is prepended before the ZIP/APK content — the file begins with a DEX header followed by valid APK (ZIP) data.
  • Flag Android apps (APKs) that are signed exclusively with v1 signature scheme (no APK Signature Scheme v2 block present) as higher risk for Janus exploitation; v2-signed APKs are not vulnerable.
  • Detect ANDROIDOS_JANUS.A: malware that embeds a small DEX payload in the APK header which decrypts and dynamically loads the actual malicious payload from assets at runtime.
  • Monitor for Android apps that register a background service triggered on device boot and subsequently connect to a remote C&C server to download and install additional malware.
  • ·Only APKs signed with v1 signature scheme are vulnerable; APKs using APK Signature Scheme v2 (introduced in Android 7.0 Nougat) are protected because the signing block covers the full file from start to the signing block, detecting any prepended DEX.
  • ·Devices running Android 5.1.1 through 8.0 are affected; the Metasploit module requires a multi/handler to be started separately as the payload handler is disabled within the module.
  • ·Mixed (v1+v2) signing is common for compatibility; on devices that support v2, rollback protection enforces v2, but on older Android versions only v1 is checked, leaving them still vulnerable.

CVSS provenance

nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vulncheck7.8HIGH
vendor_debian7.8LOW
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.