CVE-2017-13253: Buffer overflow in multiple Android DRM services
ID: 81080677-a3fa-56a8-894c-2167ec117508
STIX ID: report--81080677-a3fa-56a8-894c-2167ec117508
Feed Name: Zimperium Blog
This report describes CVE-2017-13253, a high-severity buffer overflow in Android DRM Crypto/CryptoHal/default Crypto Plugin code introduced following Project Treble changes that allow an attacker to overwrite memory outside a shared heap. The author details the vulnerable Binder/libbinder/libhwbinder data flows, supplies a PoC, discusses potential escalation paths (TEE compromise and possible root on vulnerable devices), attributes the cause to messy refactoring, and notes Google patched the issue in the March 2018 security update.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
