PT-2024-10586 · Google · Android

Published

2024-11-15

·

Updated

2024-12-18

·

CVE-2017-13314

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Android versions prior to 8.0
Description A security settings bypass is possible due to a missing permission check in the setAllowOnlyVpnForUids function of NetworkManagementService.java. This could lead to local escalation of privilege, allowing users to access non-VPN networks when they are supposed to be restricted to VPN networks, with no additional execution privileges needed. User interaction is not needed for exploitation.
Recommendations For Android versions prior to 8.0, consider restricting access to the setAllowOnlyVpnForUids function of NetworkManagementService.java to minimize the risk of exploitation. As a temporary workaround, restrict the ability of users to access non-VPN networks when they are supposed to be restricted to VPN networks.

Fix

Incorrect Default Permissions

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2017-13314

Affected Products

Android