CVE-2017-13156
65Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actepss 20%
from disclosure to weapon23 days
Published on NVDDec 6
1st PoC+23d
metasploitJul 31
VulnCheck+492d
exploitation probability
20%top 3% of all CVEs
observed exploitation
yesVulnCheck
15 public exploit(s)
An elevation of privilege vulnerability in the Android system (art). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID A-64211847.
Affected products
Google Inc. · Androidpublic PoCs found — 15✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/47601githubgithub.com/xyzAsian/Janus-CVE-2017-13156★ 15githubgithub.com/tea9/CVE-2017-13156-Janus★ 12githubgithub.com/giacomoferretti/janus-toolkit★ 11githubgithub.com/M507/CVE-2017-13156★ 3githubgithub.com/l1ackerronin/Janus-Vulnerability-CVE-2017-13156-Exploit★ 3githubgithub.com/nictjh/threatDemos★ 2githubgithub.com/caxmd/CVE-2017-13156★ 0vulncheckvulncheck.com/xdb/3373eb57b72aunverifiedvulncheckvulncheck.com/xdb/f5b5819faf5dunverifiedvulncheckvulncheck.com/xdb/c89fdeadf8fbunverifiedvulncheckvulncheck.com/xdb/6f979f8191d1unverifiedvulncheckvulncheck.com/xdb/4ffd09616ccfunverifiedvulncheckvulncheck.com/xdb/a53d146cb86bunverifiedcve_referencepacketstormsecurity.com/files/155189/Android-Janus-APK-Signature-Bypass.htmlunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.