cbcvebase.
CVE-2019-2215
published 2019-10-11

CVE-2019-2215: A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit this…

PriorityP186high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2022-05-03
Exploited in the wild
EPSS
72.10%
99.4th percentile
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit this vulnerability, however exploitation does require either the installation of a malicious local application or a separate vulnerability in a network facing application.Product: AndroidAndroid ID: A-141720095

Affected

71 ranges· showing 25
VendorProductVersion rangeFixed in
canonicalubuntu_linux
debiandebian_linux
debianlinux< linux 4.15.4-1 (bookworm)linux 4.15.4-1 (bookworm)
googleandroid
huaweialp-al00b_firmware< 10.0.0.162\(c00e156r2p4\)10.0.0.162\(c00e156r2p4\)
huaweialp-tl00b_firmware< 10.0.0.162\(c01e156r1p4\)10.0.0.162\(c01e156r1p4\)
huaweianne-al00_firmware< 9.1.0.126\(c00e126r1p7t8\)9.1.0.126\(c00e126r1p7t8\)
huaweiares-al00b_firmware< 9.1.0.165\(c00e165r2p5t8\)9.1.0.165\(c00e165r2p5t8\)
huaweiares-al10d_firmware< 9.1.0.165\(c00e165r2p5t8\)9.1.0.165\(c00e165r2p5t8\)
huaweiares-tl00chw_firmware< 8.2.0.163\(c01r2p1\)8.2.0.163\(c01r2p1\)
huaweibarca-al00_firmware< 8.0.0.377\(c00\)8.0.0.377\(c00\)
huaweiberkeley-l09_firmware< 9.1.0.351\(c432e5r1p13t8\)9.1.0.351\(c432e5r1p13t8\)
huaweiberkeley-tl10_firmware< 9.1.0.333\(c01e333r1p1t8\)9.1.0.333\(c01e333r1p1t8\)
huaweibla-al00b_firmware< 10.0.0.170\(c786e170r2p4\)10.0.0.170\(c786e170r2p4\)
huaweibla-l29c_firmware< 9.1.0.300\(c432e4r1p11t8\)9.1.0.300\(c432e4r1p11t8\)
huaweibla-tl00b_firmware< 10.0.0.170\(c01e170r1p4\)10.0.0.170\(c01e170r1p4\)
huaweicolumbia-al00a_firmware< 8.1.0.186\(c00gt\)8.1.0.186\(c00gt\)
huaweicolumbia-l29d_firmware< 9.1.0.325\(c432e4r1p12t8\)9.1.0.325\(c432e4r1p12t8\)
huaweicornell-tl10b_firmware< 9.1.0.321\(c01e320r1p1t8\)9.1.0.321\(c01e320r1p1t8\)
huaweiduke-l09i_firmware< 9.0.1.171\(c675e6r1p5t8\)9.0.1.171\(c675e6r1p5t8\)
huaweidura-al00a_firmware< 1.0.0.190\(c00\)1.0.0.190\(c00\)
huaweifigo-al00a_firmware< 9.1.0.130\(c00e115r2p8t8\)9.1.0.130\(c00e115r2p8t8\)
huaweiflorida-al20b_firmware< 9.1.0.128\(c00e112r1p6t8\)9.1.0.128\(c00e112r1p6t8\)
huaweiflorida-l03_firmware< 9.1.0.154\(c605e7r1p2t8\)9.1.0.154\(c605e7r1p2t8\)
huaweiflorida-l21_firmware< 9.1.0.154\(c605e7r1p2t8\)9.1.0.154\(c605e7r1p2t8\)

Detection & IOCsextracted from sources · hover to see the quote

hashFA86B5BC5343CA92C235304B8DCBCF4188C6BE7D4621C625564BEBD5326ED850
filename1.a
filenameDUser.dll
pathProgramData
  • Look for Android apps named 'Camero' on devices — it is the app confirmed to exploit CVE-2019-2215 (Binder UAF) for privilege escalation to kernel level.
  • Detect three co-installed malicious APKs disguised as photography and file manager tools acting in concert — a hallmark of this SideWinder campaign exploiting CVE-2019-2215.
  • On Windows systems, alert on sideloading of a fake DUser.dll into a process that loaded shell32.dll (via Rekeywiz/EFS REKEY wizard), followed by XOR decryption of a .tmp file in the same directory.
  • Alert on scheduled task creation that executes files dropped into a ProgramData subdirectory, particularly following RTF file download (CVE-2017-11882 exploitation chain associated with this actor).
  • ·The three malicious Google Play apps exploiting CVE-2019-2215 have been removed from the Play Store; detections should focus on sideloaded APKs and phishing server-hosted APKs.
  • ·CVE-2019-2215 exploitation was chained with MediaTek-SU vulnerabilities for root privileges — detections should account for multi-vulnerability exploit chains, not CVE-2019-2215 alone.
  • ·Newer SideWinder APKs found on their phishing server (not Google Play) are assessed as still in development and not yet mature enough for deliberate attack deployment.

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv7.8HIGH
vulncheck7.8HIGH
cisa7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu6.5MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.