CVE-2017-13272: Use After Free
In alarmreadygeneric of alarm.cc, there is a possible out of bounds write due to a use after free. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-67110137.
Affected Software
Event History
Frequently Asked Questions
Which Android versions are affected?
Devices running Android 7.0, 7.1.1, 7.1.2, 8.0, or 8.1 are listed as affected. The issue is in Android's Bluetooth system component.
What does an attacker need to exploit this issue?
An attacker can exploit this remotely over the network without prior privileges or user interaction. Successful exploitation could result in escalation of privilege and affect confidentiality, integrity, and availability.
What can be done if affected devices cannot be patched immediately?
The provided data does not identify configuration-based mitigations or workarounds. Prioritize applying the security fix associated with Android ID A-67110137 where available.