CVE-2017-13217 is an out-of-bounds write vulnerability in the Android bootloader's DisplayFtmItem function, affecting Android kernel versions. It stems from reading a string without null-termination verification, leading to a CVSSv3 score of 7.8 (High). This flaw allows for a secure boot bypass and local elevation of privilege, enabling code execution as a privileged process without user interaction or additional execution privileges. While no active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB) has been identified, and community discussion is minimal, the potential impact is significant.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:google:android:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.