CVE-2017-13287Improper Input Validation in INC Android

Severity
7.8HIGHNVD
EPSS
0.0%
top 98.08%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 4
Latest updateMay 14

Description

In createFromParcel of VerifyCredentialResponse.java, there is a possible invalid parcel read due to improper input validation. This could lead to local escalation of privilege if mPayload in writeToParcel were null, with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-71714464.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages2 packages

NVDgoogle/android6 versions+5
CVEListV5google_inc/android6 versions+5

🔴Vulnerability Details

2
GHSA
GHSA-256j-3jw3-gwcq: In createFromParcel of VerifyCredentialResponse2022-05-14
CVEList
CVE-2017-13287: In createFromParcel of VerifyCredentialResponse2018-04-04

📋Vendor Advisories

1
Android
CVE-2017-13287: Android Security Bulletin 2018-04-01 CVE: CVE-2017-13287 Severity: HIGH Type: EoP Affected AOSP versions: 62018-04-01
CVE-2017-13287 — Improper Input Validation | cvebase