CVE-2019-2125
published 2019-08-20CVE-2019-2125: In ChangeDefaultDialerDialog.java, there is a possible escalation of privilege due to an overlay attack. This could lead to local escalation of privilege…
PriorityP433high7.3CVSS 3.0
AVLACLPRLUIRSUCHIHAH
EPSS
0.14%
3.7th percentile
In ChangeDefaultDialerDialog.java, there is a possible escalation of privilege due to an overlay attack. This could lead to local escalation of privilege, granting privileges to a local app without the user's informed consent, with no additional privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-132275252.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — |
CVSS provenance
nvdv3.07.3HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
nvdv2.04.4MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Android
CVE-2019-2125: Android Security Bulletin 2019-08-01
CVE: CVE-2019-2125
Severity: MEDIUM
Type: EoP
Affected AOSP versions: 7
vendor_android·2019-08-01·CVSS 7.3
CVE-2019-2125 [HIGH] CVE-2019-2125: Android Security Bulletin 2019-08-01
CVE: CVE-2019-2125
Severity: MEDIUM
Type: EoP
Affected AOSP versions: 7
Android Security Bulletin 2019-08-01
CVE: CVE-2019-2125
Severity: MEDIUM
Type: EoP
Affected AOSP versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1, 9
References: A-132275252
GHSA
GHSA-mv6p-8p7v-qgqc: In ChangeDefaultDialerDialog
ghsa_unreviewed·2022-05-24
CVE-2019-2125 [HIGH] GHSA-mv6p-8p7v-qgqc: In ChangeDefaultDialerDialog
In ChangeDefaultDialerDialog.java, there is a possible escalation of privilege due to an overlay attack. This could lead to local escalation of privilege, granting privileges to a local app without the user's informed consent, with no additional privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-132275252.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-5733 edk2: Privilege escalation via heap-based buffer overflow in MakeTable() function
bugzilla·2018-10-22
CVE-2017-5733 [MEDIUM] CVE-2017-5733 edk2: Privilege escalation via heap-based buffer overflow in MakeTable() function
CVE-2017-5733 edk2: Privilege escalation via heap-based buffer overflow in MakeTable() function
In EDK II, a vulnerability exists in BaseUefiDecompressLib.c, TianoCompress.c, and UEFI specification via a heap-based buffer overflow in the MakeTable() function. An authenticated attacker could exploit this via a crafted file to escalate privileges.
External Reference:
https://edk2-docs.gitbooks.io/security-advisory/content/edk-ii-tianocompress-bounds-checking-issues.html
Upstream Bug:
https://bugzilla.tianocore.org/show_bug.cgi?id=686
Discussion:
Created edk2 tracking bugs for this issue:
Affects: epel-all [bug 1641452]
Affects: fedora-all [bug 1641451]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2019:2125 https://access.redha
Bugzilla
CVE-2017-5734 edk2: Privilege escalation via stack-based buffer overflow in MakeTable() function
bugzilla·2018-10-22
CVE-2017-5734 [MEDIUM] CVE-2017-5734 edk2: Privilege escalation via stack-based buffer overflow in MakeTable() function
CVE-2017-5734 edk2: Privilege escalation via stack-based buffer overflow in MakeTable() function
In EDK II, a vulnerability exists in BaseUefiDecompressLib.c, TianoCompress.c, and UEFI specification via a stack-based buffer overflow in the MakeTable() function. An authenticated attacker could exploit this via a crafted file to escalate privileges.
External Reference:
https://edk2-docs.gitbooks.io/security-advisory/content/edk-ii-tianocompress-bounds-checking-issues.html
Upstream Bug:
https://bugzilla.tianocore.org/show_bug.cgi?id=686
Discussion:
Created edk2 tracking bugs for this issue:
Affects: epel-all [bug 1641462]
Affects: fedora-all [bug 1641461]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2019:2125 https://access.red
Bugzilla
CVE-2017-5732 edk2: Privilege escalation via processing of malformed files in BaseUefiDecompressLib.c
bugzilla·2018-10-22
CVE-2017-5732 [MEDIUM] CVE-2017-5732 edk2: Privilege escalation via processing of malformed files in BaseUefiDecompressLib.c
CVE-2017-5732 edk2: Privilege escalation via processing of malformed files in BaseUefiDecompressLib.c
In EDK II, a vulnerability exists in BaseUefiDecompressLib.c (MdePkg/Library/BaseUefiDecompressLib). An authenticated attacker could exploit this via a crafted file to escalate privileges.
External Reference:
https://edk2-docs.gitbooks.io/security-advisory/content/edk-ii-tianocompress-bounds-checking-issues.html
Upstream Bug:
https://bugzilla.tianocore.org/show_bug.cgi?id=686
Discussion:
Created edk2 tracking bugs for this issue:
Affects: epel-all [bug 1641448]
Affects: fedora-all [bug 1641447]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2019:2125 https://access.redhat.com/errata/RHSA-2019:2125
---
This bug is now closed.
Bugzilla
CVE-2018-3613 edk2: Logic error in MdeModulePkg in EDK II firmware allows for privilege escalation by authenticated users
bugzilla·2018-10-22·CVSS 7.8
CVE-2018-3613 [HIGH] CVE-2018-3613 edk2: Logic error in MdeModulePkg in EDK II firmware allows for privilege escalation by authenticated users
CVE-2018-3613 edk2: Logic error in MdeModulePkg in EDK II firmware allows for privilege escalation by authenticated users
A logic error in MdeModulePkg in EDK II firmware may allow authenticated user to potentially bypass configuration access controls and escalate privileges via local access.
External Reference:
https://edk2-docs.gitbooks.io/security-advisory/content/edk-ii-authenticated-variable-bypass.html
Upstream Bug:
https://bugzilla.tianocore.org/show_bug.cgi?id=415
Discussion:
Created edk2 tracking bugs for this issue:
Affects: epel-all [bug 1641435]
Affects: fedora-all [bug 1641434]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2019:2125 https://access.redhat.com/errata/RHSA-2019:2125
---
This bug is now closed. Fur
Bugzilla
CVE-2017-5731 edk2: Privilege escalation via processing of malformed files in TianoCompress.c
bugzilla·2018-10-22·CVSS 7.8
CVE-2017-5731 [HIGH] CVE-2017-5731 edk2: Privilege escalation via processing of malformed files in TianoCompress.c
CVE-2017-5731 edk2: Privilege escalation via processing of malformed files in TianoCompress.c
In EDK II, a vulnerability exists in TianoCompress.c (BaseTools/Source/C/TianoCompress) from github/tianocore/edk2. An authenticated attacker could exploit this via a crafted file to escalate privileges.
External Reference:
https://edk2-docs.gitbooks.io/security-advisory/content/edk-ii-tianocompress-bounds-checking-issues.html
Upstream Bug:
https://bugzilla.tianocore.org/show_bug.cgi?id=686
Discussion:
Created edk2 tracking bugs for this issue:
Affects: epel-all [bug 1641444]
Affects: fedora-all [bug 1641443]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2019:2125 https://access.redhat.com/errata/RHSA-2019:2125
---
This bug is now
Bugzilla
CVE-2017-5735 edk2: Privilege escalation via heap-based buffer overflow in Decode() function
bugzilla·2018-10-22
CVE-2017-5735 [MEDIUM] CVE-2017-5735 edk2: Privilege escalation via heap-based buffer overflow in Decode() function
CVE-2017-5735 edk2: Privilege escalation via heap-based buffer overflow in Decode() function
In EDK II, a vulnerability exists in BaseUefiDecompressLib.c, TianoCompress.c, and UEFI specification via a heap-based buffer overflow in the Decode() function. An authenticated attacker could exploit this via a crafted file to escalate privileges.
External Reference:
https://edk2-docs.gitbooks.io/security-advisory/content/edk-ii-tianocompress-bounds-checking-issues.html
Upstream Bug:
https://bugzilla.tianocore.org/show_bug.cgi?id=686
Discussion:
Created edk2 tracking bugs for this issue:
Affects: epel-all [bug 1641468]
Affects: fedora-all [bug 1641467]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2019:2125 https://access.redhat.com/
2019-08-20
Published