CVE-2017-13284: Input Validation
In configsetstring of config.cc, it is possible to pair a second BT keyboard without user approval due to improper input validation. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-70808273.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-13284?
The severity of CVE-2017-13284 is considered to be high due to the potential for remote escalation of privilege without user interaction.
How do I fix CVE-2017-13284?
CVE-2017-13284 can be fixed by updating your Android device to a patched version provided by Google.
Which versions of Android are affected by CVE-2017-13284?
CVE-2017-13284 affects Android versions 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, and 8.1.
What does CVE-2017-13284 exploit in Android devices?
CVE-2017-13284 exploits improper input validation in the Bluetooth configuration, allowing unauthorized pairing of devices.
Is user interaction required to exploit CVE-2017-13284?
No, user interaction is not needed for exploitation of CVE-2017-13284, making it particularly concerning.