AUGUST 4, 2026
Live Feed
Return to register
Case File

CVE-2017-13209

HIGH · CVSS 7.8 EPSS 0.75% Public Exploit

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2018-01-12 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

Exhibit — Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit code execution
External Security References

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2017-13209
Severity
HIGH
CVSS
7.8
EPSS
0.75%
Android

Original Filing — NVD Description

In the ServiceManager::add function in the hardware service manager, there is an insecure permissions check based on the PID of the caller which could allow an application or service to replace a HAL service with its own service. This could lead to a local elevation of privilege enabling code execution as a privileged process with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 8.0, 8.1. Android ID: A-68217907.