CVE-2017-13314: High severity android vulnerability
In setAllowOnlyVpnForUids of NetworkManagementService.java, there is a possible security settings bypass due to a missing permission check. This could lead to local escalation of privilege allowing users to access non-VPN networks, when they are supposed to be restricted to the VPN networks, with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-13314?
CVE-2017-13314 has been classified as a critical vulnerability due to its potential for local escalation of privilege.
How do I fix CVE-2017-13314?
To mitigate CVE-2017-13314, update to an Android version that includes the patch addressing this vulnerability.
Which versions of Android are affected by CVE-2017-13314?
CVE-2017-13314 affects Android versions 7.0, 7.1.1, 7.1.2, 8.0, and 8.1.
What type of attack does CVE-2017-13314 enable?
CVE-2017-13314 enables an attacker to bypass security restrictions and access non-VPN networks when they should be limited to VPN.
Is CVE-2017-13314 a remote vulnerability?
CVE-2017-13314 is not a remote vulnerability; it requires local access to the affected device for exploitation.