CVE-2017-13278: Use After Free
In MediaPlayerService::Client::notify of MediaPlayerService.cpp, there is a possible use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-70546581.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-13278?
CVE-2017-13278 is classified as a local escalation of privilege vulnerability.
How do I fix CVE-2017-13278?
To fix CVE-2017-13278, users should update their Android devices to the latest security patches provided by Google.
Which versions of Android are affected by CVE-2017-13278?
CVE-2017-13278 affects Android versions 6.0, 6.0.1, 7.0, 7.1.1, and potentially later versions if not updated.
Is user interaction required for the exploitation of CVE-2017-13278?
No, user interaction is not needed for the exploitation of CVE-2017-13278.
What type of vulnerability is CVE-2017-13278 categorized as?
CVE-2017-13278 is categorized as a use after free vulnerability in MediaPlayerService.