CVE-2019-2215
published 2019-10-11CVE-2019-2215: A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit this…
PriorityP186high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2022-05-03
Exploited in the wild
EPSS
72.10%
99.4th percentile
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit this vulnerability, however exploitation does require either the installation of a malicious local application or a separate vulnerability in a network facing application.Product: AndroidAndroid ID: A-141720095
Affected
71 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | linux | < linux 4.15.4-1 (bookworm) | linux 4.15.4-1 (bookworm) |
| android | — | — | |
| huawei | alp-al00b_firmware | < 10.0.0.162\(c00e156r2p4\) | 10.0.0.162\(c00e156r2p4\) |
| huawei | alp-tl00b_firmware | < 10.0.0.162\(c01e156r1p4\) | 10.0.0.162\(c01e156r1p4\) |
| huawei | anne-al00_firmware | < 9.1.0.126\(c00e126r1p7t8\) | 9.1.0.126\(c00e126r1p7t8\) |
| huawei | ares-al00b_firmware | < 9.1.0.165\(c00e165r2p5t8\) | 9.1.0.165\(c00e165r2p5t8\) |
| huawei | ares-al10d_firmware | < 9.1.0.165\(c00e165r2p5t8\) | 9.1.0.165\(c00e165r2p5t8\) |
| huawei | ares-tl00chw_firmware | < 8.2.0.163\(c01r2p1\) | 8.2.0.163\(c01r2p1\) |
| huawei | barca-al00_firmware | < 8.0.0.377\(c00\) | 8.0.0.377\(c00\) |
| huawei | berkeley-l09_firmware | < 9.1.0.351\(c432e5r1p13t8\) | 9.1.0.351\(c432e5r1p13t8\) |
| huawei | berkeley-tl10_firmware | < 9.1.0.333\(c01e333r1p1t8\) | 9.1.0.333\(c01e333r1p1t8\) |
| huawei | bla-al00b_firmware | < 10.0.0.170\(c786e170r2p4\) | 10.0.0.170\(c786e170r2p4\) |
| huawei | bla-l29c_firmware | < 9.1.0.300\(c432e4r1p11t8\) | 9.1.0.300\(c432e4r1p11t8\) |
| huawei | bla-tl00b_firmware | < 10.0.0.170\(c01e170r1p4\) | 10.0.0.170\(c01e170r1p4\) |
| huawei | columbia-al00a_firmware | < 8.1.0.186\(c00gt\) | 8.1.0.186\(c00gt\) |
| huawei | columbia-l29d_firmware | < 9.1.0.325\(c432e4r1p12t8\) | 9.1.0.325\(c432e4r1p12t8\) |
| huawei | cornell-tl10b_firmware | < 9.1.0.321\(c01e320r1p1t8\) | 9.1.0.321\(c01e320r1p1t8\) |
| huawei | duke-l09i_firmware | < 9.0.1.171\(c675e6r1p5t8\) | 9.0.1.171\(c675e6r1p5t8\) |
| huawei | dura-al00a_firmware | < 1.0.0.190\(c00\) | 1.0.0.190\(c00\) |
| huawei | figo-al00a_firmware | < 9.1.0.130\(c00e115r2p8t8\) | 9.1.0.130\(c00e115r2p8t8\) |
| huawei | florida-al20b_firmware | < 9.1.0.128\(c00e112r1p6t8\) | 9.1.0.128\(c00e112r1p6t8\) |
| huawei | florida-l03_firmware | < 9.1.0.154\(c605e7r1p2t8\) | 9.1.0.154\(c605e7r1p2t8\) |
| huawei | florida-l21_firmware | < 9.1.0.154\(c605e7r1p2t8\) | 9.1.0.154\(c605e7r1p2t8\) |
Detection & IOCsextracted from sources · hover to see the quote
- →Look for Android apps named 'Camero' on devices — it is the app confirmed to exploit CVE-2019-2215 (Binder UAF) for privilege escalation to kernel level. ↗
- →Detect three co-installed malicious APKs disguised as photography and file manager tools acting in concert — a hallmark of this SideWinder campaign exploiting CVE-2019-2215. ↗
- →On Windows systems, alert on sideloading of a fake DUser.dll into a process that loaded shell32.dll (via Rekeywiz/EFS REKEY wizard), followed by XOR decryption of a .tmp file in the same directory. ↗
- →Alert on scheduled task creation that executes files dropped into a ProgramData subdirectory, particularly following RTF file download (CVE-2017-11882 exploitation chain associated with this actor). ↗
- ·The three malicious Google Play apps exploiting CVE-2019-2215 have been removed from the Play Store; detections should focus on sideloaded APKs and phishing server-hosted APKs. ↗
- ·CVE-2019-2215 exploitation was chained with MediaTek-SU vulnerabilities for root privileges — detections should account for multi-vulnerability exploit chains, not CVE-2019-2215 alone. ↗
- ·Newer SideWinder APKs found on their phishing server (not Google Play) are assessed as still in development and not yet mature enough for deliberate attack deployment. ↗
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv7.8HIGH
vulncheck7.8HIGH
cisa7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu6.5MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Kernel
list: Introduce CONFIG_LIST_HARDENED
kernel_security·2023-08-11·CVSS 7.8
CVE-2019-2025 [HIGH] list: Introduce CONFIG_LIST_HARDENED
list: Introduce CONFIG_LIST_HARDENED
Numerous production kernel configs (see [1, 2]) are choosing to enable
CONFIG_DEBUG_LIST, which is also being recommended by KSPP for hardened
configs [3]. The motivation behind this is that the option can be used
as a security hardening feature (e.g. CVE-2019-2215 and CVE-2019-2025
are mitigated by the option [4]).
The feature has never been designed with performance in mind, yet common
list manipulation is happening across hot paths all over the kernel.
Introduce CONFIG_LIST_HARDENED, which performs list pointer checking
inline, and only upon list corruption calls the reporting slow path.
To generate optimal machine code with CONFIG_LIST_HARDENED:
1. Elide checking for pointer values which upon dereference would
result in an immediate access faul
Project0
A Very Powerful Clipboard: Analysis of a Samsung in-the-wild exploit chain - Project Zero
project_zero·2022-11-01·CVSS 4.4
CVE-2019-2215 [MEDIUM] A Very Powerful Clipboard: Analysis of a Samsung in-the-wild exploit chain - Project Zero
Posted by Maddie Stone, Project Zero
Note: The three vulnerabilities discussed in this blog were all fixed in Samsung’s March 2021 release. They were fixed as CVE-2021-25337, CVE-2021-25369, CVE-2021-25370. To ensure your Samsung device is up-to-date under settings you can check that your device is running SMR Mar-2021 or later.
As defenders, in-the-wild exploit samples give us important insight into what attackers are really doing. We get the “ground truth” data about the vulnerabilities and exploit techniques they’re using, which then informs our further research and guidance to security teams on what could have the biggest impact or return on investment. To do this, we need to know that the vulnerabilities and exploit samples were found in-the-wild. Over the past few years the
GHSA
GHSA-m7g6-9cwp-6jgm: A use-after-free in binder
ghsa_unreviewed·2022-05-24
CVE-2019-2215 [HIGH] CWE-416 GHSA-m7g6-9cwp-6jgm: A use-after-free in binder
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit this vulnerability, however exploitation does require either the installation of a malicious local application or a separate vulnerability in a network facing application.Product: AndroidAndroid ID: A-141720095
Project0
The More You Know, The More You Know You Don’t Know - Project Zero
project_zero·2022-04-01
CVE-2016-4654 The More You Know, The More You Know You Don’t Know - Project Zero
A Year in Review of 0-days Used In-the-Wild in 2021
Posted by Maddie Stone, Google Project Zero
This is our third annual year in review of 0-days exploited in-the-wild [2020, 2019]. Each year we’ve looked back at all of the detected and disclosed in-the-wild 0-days as a group and synthesized what we think the trends and takeaways are. The goal of this report is not to detail each individual exploit, but instead to analyze the exploits from the year as a group, looking for trends, gaps, lessons learned, successes, etc. If you’re interested in the analysis of individual exploits, please check out our root cause analysis repository.
We perform and share this analysis in order to make 0-day hard. We want it to be more costly, more resource intensive, and overall more difficult for
Project0
Root Cause Analyses for 0-day In-the-Wild Exploits - Project Zero
project_zero·2020-07-01
CVE-2019-1107 Root Cause Analyses for 0-day In-the-Wild Exploits - Project Zero
Posted by Maddie Stone, Project Zero
When a 0-day is exploited in the wild AND it is detected, we need to use that as an opportunity to learn as much as possible about the vulnerability and the exploit if we hope to make 0-day hard. One of the main methods to do that is to perform a root cause analysis (RCA) on the 0-day.
Our effort on this began in earnest in the last quarter of 2019. Today we are beginning to publish the root cause analyses for 0-days exploited in the wild that we have completed. While we’re publishing some in bulk now to play “catch-up”, in the future we plan to post each one in a timely manner after it’s detected and disclosed. We think publishing technical details in a timely manner is important for transparency and so that the whole of the security community can
Project0
Detection Deficit: A Year in Review of 0-days Used In-The-Wild in 2019 - Project Zero
project_zero·2020-07-01
CVE-2016-5195 Detection Deficit: A Year in Review of 0-days Used In-The-Wild in 2019 - Project Zero
Posted by Maddie Stone, Project Zero
In May 2019, Project Zero released our tracking spreadsheet for 0-days used “in the wild” and we started a more focused effort on analyzing and learning from these exploits. This is another way Project Zero is trying to make zero-day hard. This blog post synthesizes many of our efforts and what we’ve seen over the last year. We provide a review of what we can learn from 0-day exploits detected as used in the wild in 2019. In conjunction with this blog post, we are also publishing another blog post today about our root cause analysis work that informed the conclusions in this Year in Review. We are also releasing 8 root cause analyses that we have done for in-the-wild 0-days from 2019.
When I had the idea for this “Year in Review” blog post, I immedi
VulnCheck
Mediatek Multiple Chipsets Insufficient Input Validation Vulnerability
vulncheck·2020·CVSS 7.8
CVE-2020-0069 [HIGH] CWE-787 Mediatek Multiple Chipsets Insufficient Input Validation Vulnerability
Mediatek Multiple Chipsets Insufficient Input Validation Vulnerability
Multiple MediaTek chipsets contain an insufficient input validation vulnerability and have missing SELinux restrictions in the Command Queue drivers ioctl handlers. This causes an out-of-bounds write leading to privilege escalation. This vulnerability was observed chained with CVE-2019-2215 and CVE-2020-0041 under exploit chain "AbstractEmu."
Affected: MediaTek Multiple Chipsets
Required Action: Apply updates per vendor instructions.
Exploitation References: https://www.lookout.com/threat-intelligence/article/lookout-discovers-global-rooting-malware-campaign; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
Exploit PoC: https://vulncheck.com/xdb/9a931c619e3c; https://vulncheck.com
VulnCheck
Android Kernel Out-of-Bounds Write Vulnerability
vulncheck·2020·CVSS 7.8
CVE-2020-0041 [HIGH] CWE-20 Android Kernel Out-of-Bounds Write Vulnerability
Android Kernel Out-of-Bounds Write Vulnerability
Android Kernel binder_transaction of binder.c contains an out-of-bounds write vulnerability due to an incorrect bounds check that could allow for local privilege escalation. This vulnerability was observed chained with CVE-2019-2215 and CVE-2020-0069 under exploit chain "AbstractEmu."
Affected: Android Android
Required Action: Apply updates per vendor instructions.
Exploitation References: https://www.lookout.com/threat-intelligence/article/lookout-discovers-global-rooting-malware-campaign; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
Exploit PoC: https://vulncheck.com/xdb/b8a8ac784158; https://vulncheck.com/xdb/95ece15b5070; https://vulncheck.com/xdb/c2368cc50b93
Remediation Due: 2022-05-03
OSV
linux, linux-aws, linux-kvm vulnerabilities
osv·2019-11-13·CVSS 6.5
[MEDIUM] linux, linux-aws, linux-kvm vulnerabilities
linux, linux-aws, linux-kvm vulnerabilities
Stephan van Schaik, Alyssa Milburn, Sebastian Österlund, Pietro Frigo,
Kaveh Razavi, Herbert Bos, Cristiano Giuffrida, Giorgi Maisuradze, Moritz
Lipp, Michael Schwarz, Daniel Gruss, and Jo Van Bulck discovered that Intel
processors using Transactional Synchronization Extensions (TSX) could
expose memory contents previously stored in microarchitectural buffers to a
malicious process that is executing on the same CPU core. A local attacker
could use this to expose sensitive information. (CVE-2019-11135)
It was discovered that the Intel i915 graphics chipsets allowed userspace
to modify page table entries via writes to MMIO from the Blitter Command
Streamer and expose kernel memory information. A local attacker could use
this to expose sensitive i
OSV
linux vulnerability
osv·2019-11-13·CVSS 6.5
CVE-2019-0155 [MEDIUM] linux vulnerability
linux vulnerability
USN-4186-1 fixed vulnerabilities in the Linux kernel. It was discovered
that the kernel fix for CVE-2019-0155 (i915 missing Blitter Command
Streamer check) was incomplete on 64-bit Intel x86 systems. This
update addresses the issue.
We apologize for the inconvenience.
Original advisory details:
Stephan van Schaik, Alyssa Milburn, Sebastian Österlund, Pietro Frigo,
Kaveh Razavi, Herbert Bos, Cristiano Giuffrida, Giorgi Maisuradze, Moritz
Lipp, Michael Schwarz, Daniel Gruss, and Jo Van Bulck discovered that Intel
processors using Transactional Synchronization Extensions (TSX) could
expose memory contents previously stored in microarchitectural buffers to a
malicious process that is executing on the same CPU core. A local attacker
could use this to expose sensitive inf
Project0
Bad Binder: Android In-The-Wild Exploit - Project Zero
project_zero·2019-11-01·CVSS 7.8
CVE-2019-2215 [HIGH] Bad Binder: Android In-The-Wild Exploit - Project Zero
Posted by Maddie Stone, Project Zero
Introduction
On October 3, 2019, we disclosed issue 1942 (CVE-2019-2215), which is a use-after-free in Binder in the Android kernel. The bug is a local privilege escalation vulnerability that allows for a full compromise of a vulnerable device. If chained with a browser renderer exploit, this bug could fully compromise a device through a malicious website.
We reported this bug under a 7-day disclosure deadline rather than the normal 90-day disclosure deadline. We made this decision based on credible evidence that an exploit for this vulnerability exists in the wild and that it's highly likely that the exploit was being actively used against users.
In May 2019, Project Zero published a blog post and spreadsheet for tracking “in-the-wild” 0-day exp
OSV
CVE-2019-2215: A use-after-free in binder
osv·2019-10-11·CVSS 7.8
CVE-2019-2215 [HIGH] CVE-2019-2215: A use-after-free in binder
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit this vulnerability, however exploitation does require either the installation of a malicious local application or a separate vulnerability in a network facing application.Product: AndroidAndroid ID: A-141720095
VulnCheck
Android Kernel Use-After-Free Vulnerability
vulncheck·2019·CVSS 7.8
CVE-2019-2215 [HIGH] CWE-416 Android Kernel Use-After-Free Vulnerability
Android Kernel Use-After-Free Vulnerability
Android Kernel contains a use-after-free vulnerability in binder.c that allows for privilege escalation from an application to the Linux Kernel. This vulnerability was observed chained with CVE-2020-0041 and CVE-2020-0069 under exploit chain "AbstractEmu."
Affected: Android Android
Required Action: Apply updates per vendor instructions.
Exploitation References: https://bugs.chromium.org/p/project-zero/issues/detail?id=1942#c7; https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit; https://www.trendmicro.com/en_us/research/20/a/first-active-attack-exploiting-cve-2019-2215-found-on-google-play-linked-to-sidewinder-apt-group.html; https://www.trendmicro.com/en_us/research/20/l/sidewinder-leverages-south-asian-t
Project0
Project Zero RCA: CVE-2019-2215: Android use-after-free in Binder
project_zero·CVSS 7.8
CVE-2019-2215 [HIGH] Project Zero RCA: CVE-2019-2215: Android use-after-free in Binder
# CVE-2019-2215: Android use-after-free in Binder
*Maddie Stone, Project Zero (Originally posted on [Project Zero blog](https://googleprojectzero.blogspot.com/p/rca.html) 2020-07-27)*
## The Basics
**Disclosure or Patch Date:** 26 September 2019
**Product:** Google Android
**Advisory:** https://source.android.com/security/bulletin/2019-10-01#kernel-b
**Affected Versions:** Pre-Oct 6 2019 SPL for devices released prior to Fall 2019
**First Patched Version:** 6 Oct 2019 SPL+
**Issue/Bug Report:** https://bugs.chromium.org/p/project-zero/issues/detail?id=1942
**Patch CL:** https://android-review.googlesource.com/c/kernel/common/+/609966
**Bug-Introducing CL:** Unknown
**Reporter(s):** Maddie Stone of Google Project Zero
## The Code
**Proof-of-concept:** https://bugs.chromium.org/
CISA
Mediatek Multiple Chipsets Insufficient Input Validation Vulnerability
cisa·2021-11-03·CVSS 7.8
CVE-2020-0069 [HIGH] CWE-787 Mediatek Multiple Chipsets Insufficient Input Validation Vulnerability
Vulnerability: Mediatek Multiple Chipsets Insufficient Input Validation Vulnerability
Affected: MediaTek Multiple Chipsets
Multiple MediaTek chipsets contain an insufficient input validation vulnerability and have missing SELinux restrictions in the Command Queue drivers ioctl handlers. This causes an out-of-bounds write leading to privilege escalation. This vulnerability was observed chained with CVE-2019-2215 and CVE-2020-0041 under exploit chain "AbstractEmu."
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2020-0069
Remediation Due Date: 2022-05-03
CISA
Android Kernel Out-of-Bounds Write Vulnerability
cisa·2021-11-03·CVSS 7.8
CVE-2020-0041 [HIGH] CWE-20 Android Kernel Out-of-Bounds Write Vulnerability
Vulnerability: Android Kernel Out-of-Bounds Write Vulnerability
Affected: Android Android Kernel
Android Kernel binder_transaction of binder.c contains an out-of-bounds write vulnerability due to an incorrect bounds check that could allow for local privilege escalation. This vulnerability was observed chained with CVE-2019-2215 and CVE-2020-0069 under exploit chain "AbstractEmu."
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2020-0041
Remediation Due Date: 2022-05-03
CISA
Android Kernel Use-After-Free Vulnerability
cisa·2021-11-03·CVSS 7.8
CVE-2019-2215 [HIGH] CWE-416 Android Kernel Use-After-Free Vulnerability
Vulnerability: Android Kernel Use-After-Free Vulnerability
Affected: Android Android Kernel
Android Kernel contains a use-after-free vulnerability in binder.c that allows for privilege escalation from an application to the Linux Kernel. This vulnerability was observed chained with CVE-2020-0041 and CVE-2020-0069 under exploit chain "AbstractEmu."
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2019-2215
Remediation Due Date: 2022-05-03
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2019-11-13·CVSS 6.5
CVE-2018-12207 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Stephan van Schaik, Alyssa Milburn, Sebastian Österlund, Pietro Frigo,
Kaveh Razavi, Herbert Bos, Cristiano Giuffrida, Giorgi Maisuradze, Moritz
Lipp, Michael Schwarz, Daniel Gruss, and Jo Van Bulck discovered that Intel
processors using Transactional Synchronization Extensions (TSX) could
expose memory contents previously stored in microarchitectural buffers to a
malicious process that is executing on the same CPU core. A local attacker
could use this to expose sensitive information. (CVE-2019-11135)
It was discovered that the Intel i915 graphics chipsets allowed userspace
to modify page table entries via writes to MMIO from the Blitter Command
Streamer and expose kernel memory informat
Ubuntu
Linux kernel vulnerability
vendor_ubuntu·2019-11-13·CVSS 6.5
CVE-2019-0155 [MEDIUM] Linux kernel vulnerability
Title: Linux kernel vulnerability
Summary: Several security issues were fixed in the Linux kernel.
USN-4186-1 fixed vulnerabilities in the Linux kernel. It was discovered
that the kernel fix for CVE-2019-0155 (i915 missing Blitter Command
Streamer check) was incomplete on 64-bit Intel x86 systems. This
update addresses the issue.
We apologize for the inconvenience.
Original advisory details:
Stephan van Schaik, Alyssa Milburn, Sebastian Österlund, Pietro Frigo,
Kaveh Razavi, Herbert Bos, Cristiano Giuffrida, Giorgi Maisuradze, Moritz
Lipp, Michael Schwarz, Daniel Gruss, and Jo Van Bulck discovered that Intel
processors using Transactional Synchronization Extensions (TSX) could
expose memory contents previously stored in microarchitectural buffers to a
malicious process that is executi
Red Hat
kernel: Use-after-free in binder.c
vendor_redhat·2019-10-16·CVSS 7.8
CVE-2019-2215 [HIGH] CWE-119 kernel: Use-after-free in binder.c
kernel: Use-after-free in binder.c
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit this vulnerability, however exploitation does require either the installation of a malicious local application or a separate vulnerability in a network facing application.Product: AndroidAndroid ID: A-141720095
A flaw was found in the Linux kernel’s Android compatibility functionality. A local attacker can abuse a use-after-free flaw in the Android binder code to corrupt memory or possibly escalate privileges.
Mitigation: There is no mitigation required for this flaw as it does not affect shipping Red Hat Enterprise Linux kernels.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: kernel (
Android
CVE-2019-2215: Binder
vendor_android·2019-10-01·CVSS 7.8
CVE-2019-2215 [HIGH] CVE-2019-2215: Binder
Android Security Bulletin 2019-10-01
CVE: CVE-2019-2215
Severity: HIGH
Type: EoP
Component: Binder
References: A-141720095
Debian
CVE-2019-2215: linux - A use-after-free in binder.c allows an elevation of privilege from an applicatio...
vendor_debian·2019·CVSS 7.8
CVE-2019-2215 [HIGH] CVE-2019-2215: linux - A use-after-free in binder.c allows an elevation of privilege from an applicatio...
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit this vulnerability, however exploitation does require either the installation of a malicious local application or a separate vulnerability in a network facing application.Product: AndroidAndroid ID: A-141720095
Scope: local
bookworm: resolved (fixed in 4.15.4-1)
bullseye: resolved (fixed in 4.15.4-1)
forky: resolved (fixed in 4.15.4-1)
sid: resolved (fixed in 4.15.4-1)
trixie: resolved (fixed in 4.15.4-1)
No detection rules found.
Exploit-DB
Android Binder - Use-After-Free (Metasploit)
exploitdb·2020-02-24·CVSS 7.8
CVE-2019-2215 [HIGH] Android Binder - Use-After-Free (Metasploit)
Android Binder - Use-After-Free (Metasploit)
---
##
# This module requires Metasploit: https://metasploit.com/download
# Current source: https://github.com/rapid7/metasploit-framework
##
class MetasploitModule "Android Binder Use-After-Free Exploit",
'Description' => %q{
},
'License' => MSF_LICENSE,
'Author' => [
'Jann Horn', # discovery and exploit
'Maddie Stone', # discovery and exploit
'grant-h', # Qu1ckR00t
'timwr', # metasploit module
],
'References' => [
[ 'CVE', '2019-2215' ],
[ 'URL', 'https://bugs.chromium.org/p/project-zero/issues/detail?id=1942' ],
[ 'URL', 'https://hernan.de/blog/2019/10/15/tailoring-cve-2019-2215-to-achieve-root/' ],
[ 'URL', 'https://github.com/grant-h/qu1ckr00t/blob/master/native/poc.c' ],
],
'DisclosureDate' => "Sep 26 2019",
'SessionTypes' => [ 'meterpr
Exploit-DB
Android - Binder Driver Use-After-Free
exploitdb·2019-10-04
CVE-2019-2215 Android - Binder Driver Use-After-Free
Android - Binder Driver Use-After-Free
---
The following issue exists in the android-msm-wahoo-4.4-pie branch of https://android.googlesource.com/kernel/msm (and possibly others):
There is a use-after-free of the wait member in the binder_thread struct in the binder driver at /drivers/android/binder.c.
As described in the upstream commit:
“binder_poll() passes the thread->wait waitqueue that
can be slept on for work. When a thread that uses
epoll explicitly exits using BINDER_THREAD_EXIT,
the waitqueue is freed, but it is never removed
from the corresponding epoll data structure. When
the process subsequently exits, the epoll cleanup
code tries to access the waitlist, which results in
a use-after-free.”
The following proof-of-concept will show the UAF crash in a kernel build with KASA
Metasploit
Android Binder Use-After-Free Exploit
metasploit·CVSS 7.8
CVE-2019-2215 [HIGH] Android Binder Use-After-Free Exploit
Android Binder Use-After-Free Exploit
This module exploits CVE-2019-2215, which is a use-after-free in Binder in the Android kernel. The bug is a local privilege escalation vulnerability that allows for a full compromise of a vulnerable device. If chained with a browser renderer exploit, this bug could fully compromise a device through a malicious website. The freed memory is replaced with an iovec structure in order to leak a pointer to the task_struct. Finally the bug is triggered again in order to overwrite the addr_limit, making all memory (including kernel memory) accessible as part of the user-space memory range in our process and allowing arbitrary reading and writing of kernel memory.
Qualys
Expand Your Vulnerability & Patch Management Program to Mobile Devices with Qualys VMDR | Qualys
blogs_qualys·2021-02-10·CVSS 7.8
[HIGH] Expand Your Vulnerability & Patch Management Program to Mobile Devices with Qualys VMDR | Qualys
As mobile devices have become ubiquitous in almost every business process, whether in bank branches, manufacturing sites or retail stores, they are now hosting business applications and data that is subject to regulatory compliance and security. With access to critical corporate resources inside the corporate network, these mobile devices have become critical assets for the organization.
### Mobile Attack Surface Challenges
Alongside this trend, there has been a drastic rise in Android, iOS, and iPadOS vulnerabilities and an increased number of vulnerable apps distributed from authorized app stores. Through these vectors, mobile devices have become preferred targets for attackers to gain an entry point into corporate networks. Last year, for example, 900 million Apple iOS users were affe
Qualys
Expand Your Vulnerability & Patch Management Program to Mobile Devices with Qualys VMDR
blogs_qualys·2021-02-10·CVSS 7.8
[HIGH] Expand Your Vulnerability & Patch Management Program to Mobile Devices with Qualys VMDR
As mobile devices have become ubiquitous in almost every business process, whether in bank branches, manufacturing sites or retail stores, they are now hosting business applications and data that is subject to regulatory compliance and security. With access to critical corporate resources inside the corporate network, these mobile devices have become critical assets for the organization.
## Mobile Attack Surface Challenges
Alongside this trend, there has been a drastic rise in Android, iOS, and iPadOS vulnerabilities and an increased number of vulnerable apps distributed from authorized app stores. Through these vectors, mobile devices have become preferred targets for attackers to gain an entry point into corporate networks. Last year, for example, 900 million Apple iOS users were affec
Trendmicro
SideWinder Uses South Asian Issues for Spear Phishing, Mobile Attacks
blogs_trendmicro·2020-12-09
SideWinder Uses South Asian Issues for Spear Phishing, Mobile Attacks
APT & Targeted Attacks
## SideWinder Uses South Asian Issues for Spear Phishing, Mobile Attacks
While tracking the activities of the SideWinder group, we identified a server used to deliver a malicious LNK file and host multiple credential phishing pages. In addition, we also found multiple Android APK files on their phishing server.
By: Joseph C Chen, Jaromir Horejsi, Ecular Xu 2020/12/09 Read time: ( words)
Save to Folio
While tracking the activities of the SideWinder group, which has become infamous for targeting the South Asia region and its surrounding countries, we identified a server used to deliver a malicious LNK file and host multiple credential phishing pages. We learned that these pages were copied from their victims’ webmail login pages and subsequently modified for phish
Trendmicro
SideWinder Uses South Asian Issues for Spear Phishing, Mobile Attacks
blogs_trendmicro·2020-12-09
SideWinder Uses South Asian Issues for Spear Phishing, Mobile Attacks
APT y ataques dirigidos
## SideWinder Uses South Asian Issues for Spear Phishing, Mobile Attacks
While tracking the activities of the SideWinder group, we identified a server used to deliver a malicious LNK file and host multiple credential phishing pages. In addition, we also found multiple Android APK files on their phishing server.
By: Joseph C Chen, Jaromir Horejsi, Ecular Xu Dec 09, 2020 Read time: ( words)
Save to Folio
While tracking the activities of the SideWinder group, which has become infamous for targeting the South Asia region and its surrounding countries, we identified a server used to deliver a malicious LNK file and host multiple credential phishing pages. We learned that these pages were copied from their victims’ webmail login pages and subsequently modified for ph
Trendmicro
SideWinder Uses South Asian Issues for Spear Phishing, Mobile Attacks
blogs_trendmicro·2020-12-09
SideWinder Uses South Asian Issues for Spear Phishing, Mobile Attacks
APT & attacchi mirati
## SideWinder Uses South Asian Issues for Spear Phishing, Mobile Attacks
While tracking the activities of the SideWinder group, we identified a server used to deliver a malicious LNK file and host multiple credential phishing pages. In addition, we also found multiple Android APK files on their phishing server.
By: Joseph C Chen, Jaromir Horejsi, Ecular Xu Dec 09, 2020 Read time: ( words)
Save to Folio
While tracking the activities of the SideWinder group, which has become infamous for targeting the South Asia region and its surrounding countries, we identified a server used to deliver a malicious LNK file and host multiple credential phishing pages. We learned that these pages were copied from their victims’ webmail login pages and subsequently modified for phis
Trendmicro
SideWinder Uses South Asian Issues for Spear Phishing, Mobile Attacks
blogs_trendmicro·2020-12-09
SideWinder Uses South Asian Issues for Spear Phishing, Mobile Attacks
APT & Targeted Attacks
# SideWinder Uses South Asian Issues for Spear Phishing, Mobile Attacks
While tracking the activities of the SideWinder group, we identified a server used to deliver a malicious LNK file and host multiple credential phishing pages. In addition, we also found multiple Android APK files on their phishing server.
By: Joseph C Chen, Jaromir Horejsi, Ecular Xu
2020/12/09
Read time: ( words)
Save to Folio
While tracking the activities of the SideWinder group, which has become infamous for targeting the South Asia region and its surrounding countries, we identified a server used to deliver a malicious LNK file and host multiple credential phishing pages. We learned that these pages were copied from their victims’ webmail login pages and subsequently modified for phish
Trendmicro
SideWinder Uses South Asian Issues for Spear Phishing, Mobile Attacks
blogs_trendmicro·2020-12-09
SideWinder Uses South Asian Issues for Spear Phishing, Mobile Attacks
APT & Targeted Attacks
## SideWinder Uses South Asian Issues for Spear Phishing, Mobile Attacks
While tracking the activities of the SideWinder group, we identified a server used to deliver a malicious LNK file and host multiple credential phishing pages. In addition, we also found multiple Android APK files on their phishing server.
By: Joseph C Chen, Jaromir Horejsi, Ecular Xu Dec 09, 2020 Read time: ( words)
Save to Folio
While tracking the activities of the SideWinder group, which has become infamous for targeting the South Asia region and its surrounding countries, we identified a server used to deliver a malicious LNK file and host multiple credential phishing pages. We learned that these pages were copied from their victims’ webmail login pages and subsequently modified for phi
Trendmicro
SideWinder Uses South Asian Issues for Spear Phishing, Mobile Attacks
blogs_trendmicro·2020-12-09
SideWinder Uses South Asian Issues for Spear Phishing, Mobile Attacks
APT und gezielte Angriffe
## SideWinder Uses South Asian Issues for Spear Phishing, Mobile Attacks
While tracking the activities of the SideWinder group, we identified a server used to deliver a malicious LNK file and host multiple credential phishing pages. In addition, we also found multiple Android APK files on their phishing server.
By: Joseph C Chen, Jaromir Horejsi, Ecular Xu Dec 09, 2020 Read time: ( words)
Save to Folio
While tracking the activities of the SideWinder group, which has become infamous for targeting the South Asia region and its surrounding countries, we identified a server used to deliver a malicious LNK file and host multiple credential phishing pages. We learned that these pages were copied from their victims’ webmail login pages and subsequently modified for
Checkpoint
13th January – Threat Intelligence Bulletin
blogs_checkpoint·2020-01-13·CVSS 7.8
CVE-2019-2215 [HIGH] 13th January – Threat Intelligence Bulletin
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 13th January – Threat Intelligence Bulletin
For the latest discoveries in cyber research for the week of 13th January 2020, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
Austria’s foreign ministry has suffered a serious cyber-attack, allegedly conducted by a foreign state.
US government-funded low-cost UMX mobile phones include preinstalled “unremovable” malware. The malware, a variant of HiddenAds, is suspected to be of Chinese origin, as is the UMX phone itself.
Three malicious
Trendmicro
INTERPOL Collaboration Reduces Cryptojacking by 78%
blogs_trendmicro·2020-01-10·CVSS 7.8
[HIGH] INTERPOL Collaboration Reduces Cryptojacking by 78%
Cyber Crime
# INTERPOL Collaboration Reduces Cryptojacking by 78%
Learn about how Trend Micro’s collaboration with INTERPOL’s Global Complex for Innovation helped reduce cryptojacking by 78% in Southeast Asia. Also, three malicious apps in the Google Play Store may be linked to the SideWinder threat group.
By: Jon Clay
2020/01/10
Read time: ( words)
Save to Folio
Welcome to our weekly roundup, where we share what you need to know about the cybersecurity news and events that happened over the past few days. This week, learn about how Trend Micro’s collaboration with INTERPOL’s Global Complex for Innovation helped reduce cryptojacking by 78% in Southeast Asia. Also, read about three malicious apps in the Google Play Store that may be linked to the SideWinder threat group.
Read on:
##
Trendmicro
First Binder Exploit Linked to SideWinder APT Group
blogs_trendmicro·2020-01-06·CVSS 7.8
CVE-2019-2215 [HIGH] First Binder Exploit Linked to SideWinder APT Group
Mobile
## First Binder Exploit Linked to SideWinder APT Group
We found malicious apps that work together to compromise devices and collect user data. One of the apps, called Camero, exploits CVE-2019-2215, a flaw that exists in Binder. This is the first instance in the wild that exploits said UAF vulnerability.
By: Ecular Xu, Joseph C Chen Jan 06, 2020 Read time: ( words)
Save to Folio
Updated January 8, 2020 5PM EST with a video showing the exploit of CVE-2019-2215.
We found three malicious apps in the Google Play Store that work together to compromise a victim’s device and collect user information. One of these apps, called Camero, exploits CVE-2019-2215 , a vulnerability that exists in Binder (the main Inter-Process Communication system in Android). This is the first known active
Trendmicro
First Binder Exploit Linked to SideWinder APT Group
blogs_trendmicro·2020-01-06·CVSS 7.8
CVE-2019-2215 [HIGH] First Binder Exploit Linked to SideWinder APT Group
Mobilgeräte
## First Binder Exploit Linked to SideWinder APT Group
We found malicious apps that work together to compromise devices and collect user data. One of the apps, called Camero, exploits CVE-2019-2215, a flaw that exists in Binder. This is the first instance in the wild that exploits said UAF vulnerability.
By: Ecular Xu, Joseph C Chen Jan 06, 2020 Read time: ( words)
Save to Folio
Updated January 8, 2020 5PM EST with a video showing the exploit of CVE-2019-2215.
We found three malicious apps in the Google Play Store that work together to compromise a victim’s device and collect user information. One of these apps, called Camero, exploits CVE-2019-2215 , a vulnerability that exists in Binder (the main Inter-Process Communication system in Android). This is the first known ac
Trendmicro
First Binder Exploit Linked to SideWinder APT Group
blogs_trendmicro·2020-01-06·CVSS 7.8
CVE-2019-2215 [HIGH] First Binder Exploit Linked to SideWinder APT Group
Mobile
# First Binder Exploit Linked to SideWinder APT Group
We found malicious apps that work together to compromise devices and collect user data. One of the apps, called Camero, exploits CVE-2019-2215, a flaw that exists in Binder. This is the first instance in the wild that exploits said UAF vulnerability.
By: Ecular Xu, Joseph C Chen
2020/01/06
Read time: ( words)
Save to Folio
Updated January 8, 2020 5PM EST with a video showing the exploit of CVE-2019-2215.
We found three malicious apps in the Google Play Store that work together to compromise a victim’s device and collect user information. One of these apps, called Camero, exploits CVE-2019-2215, a vulnerability that exists in Binder (the main Inter-Process Communication system in Android). This is the first known active att
Trendmicro
First Binder Exploit Linked to SideWinder APT Group
blogs_trendmicro·2020-01-06·CVSS 7.8
CVE-2019-2215 [HIGH] First Binder Exploit Linked to SideWinder APT Group
Dispositivos móviles
## First Binder Exploit Linked to SideWinder APT Group
We found malicious apps that work together to compromise devices and collect user data. One of the apps, called Camero, exploits CVE-2019-2215, a flaw that exists in Binder. This is the first instance in the wild that exploits said UAF vulnerability.
By: Ecular Xu, Joseph C Chen Jan 06, 2020 Read time: ( words)
Save to Folio
Updated January 8, 2020 5PM EST with a video showing the exploit of CVE-2019-2215.
We found three malicious apps in the Google Play Store that work together to compromise a victim’s device and collect user information. One of these apps, called Camero, exploits CVE-2019-2215 , a vulnerability that exists in Binder (the main Inter-Process Communication system in Android). This is the first
Trendmicro
First Binder Exploit Linked to SideWinder APT Group
blogs_trendmicro·2020-01-06·CVSS 7.8
CVE-2019-2215 [HIGH] First Binder Exploit Linked to SideWinder APT Group
Mobile
## First Binder Exploit Linked to SideWinder APT Group
We found malicious apps that work together to compromise devices and collect user data. One of the apps, called Camero, exploits CVE-2019-2215, a flaw that exists in Binder. This is the first instance in the wild that exploits said UAF vulnerability.
By: Ecular Xu, Joseph C Chen 2020/01/06 Read time: ( words)
Save to Folio
Updated January 8, 2020 5PM EST with a video showing the exploit of CVE-2019-2215.
We found three malicious apps in the Google Play Store that work together to compromise a victim’s device and collect user information. One of these apps, called Camero, exploits CVE-2019-2215 , a vulnerability that exists in Binder (the main Inter-Process Communication system in Android). This is the first known active at
Checkpoint
7th October – Threat Intelligence Bulletin
blogs_checkpoint·2019-10-07
CVE-2019-2215 7th October – Threat Intelligence Bulletin
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 7th October – Threat Intelligence Bulletin
For the latest discoveries in cyber research for the week of 2nd October 2019, please download our Threat Intelligence Bulletin
TOp attacks AND breacheS
Check Point Research has uncovered new information on an espionage campaign suspected to be conducted by the Egyptian government . The targets of the campaign are journalists, politicians, human rights activists and lawyers in Egypt. Most of the activity was conducted using malicious mobile apps, used to gather login c
arXiv
TikTag: Breaking ARM's Memory Tagging Extension with Speculative Execution
arxiv_fulltext·2024-06-13
TikTag: Breaking ARM's Memory Tagging Extension with Speculative Execution
: Breaking ARM's Memory Tagging Extension with Speculative Execution
fancyplain
Rev.
\ of LastPage
Juhee Kim
Seoul National University
[email protected]
Jinbum Park
Samsung Research
[email protected]
Sihyeon Roh
Seoul National University
[email protected]
Jaeyoung Chung
Seoul National University
[email protected]
Youngjoo Lee
Seoul National University
[email protected]
Taesoo Kim
Samsung Research and
Georgia Institute of Technology
[email protected]
Byoungyoung Lee
Seoul National University
[email protected]
## Abstract
ARM Memory Tagging Extension (MTE) is a new hardware feature
introduced in ARMv8.5-A architecture, aiming to detect memory
corruption vulnerabilities.
The low overhead of MTE makes it an attractive solution to mitigate
memory corruptio
arXiv
Technical Report -- Expected Exploitability: Predicting the Development of Functional Vulnerability Exploits
arxiv_fulltext·2022-02-03
Technical Report -- Expected Exploitability: Predicting the Development of Functional Vulnerability Exploits
Octavian Suciu,
Connor Nelson ,
Zhuoer Lyu ,
Tiffany Bao ,
Tudor Dumitras
University of Maryland, College Park
State University
comment
\@IEEEpubidpullup6.5
Network and Distributed Systems Security (NDSS) Symposium 2020
23-26 February 2020, San Diego, CA, USA
ISBN 1-891562-61-4
https://dx.doi.org/10.14722/ndss.2020.23xxx
www.ndss-symposium.org
[ ]
comment
empty
## Abstract
Assessing the exploitability of software vulnerabilities at the time of disclosure is difficult and error-prone, as features extracted via technical analysis by existing metrics are poor predictors for exploit development.
Moreover, exploitability assessments suffer from a class bias because ``not exploitable'' labels could be inaccurate.
To overcome these challenges, we propose a new metric, called Expecte
Bugzilla
CVE-2019-2215 kernel: Use-after-free in binder.c
bugzilla·2020-02-21·CVSS 7.8
CVE-2019-2215 [HIGH] CVE-2019-2215 kernel: Use-after-free in binder.c
CVE-2019-2215 kernel: Use-after-free in binder.c
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit this vulnerability, however exploitation does require either the installation of a malicious local application or a separate vulnerability in a network facing application.Product: AndroidAndroid ID: A-141720095
Upstream patch:
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/drivers/android/binder.c?h=linux-4.14.y&id=7a3cee43e935b9d526ad07f20bf005ba7e74d05b
References:
https://seclists.org/fulldisclosure/2019/Oct/38
https://github.com/marcinguy/CVE-2019-2215/
https://bugs.chromium.org/p/project-zero/issues/detail?id=1942
Discussion:
Mitigation:
There is no mitigation
http://packetstormsecurity.com/files/154911/Android-Binder-Use-After-Free.htmlhttp://packetstormsecurity.com/files/155212/Slackware-Security-Advisory-Slackware-14.2-kernel-Updates.htmlhttp://packetstormsecurity.com/files/156495/Android-Binder-Use-After-Free.htmlhttp://seclists.org/fulldisclosure/2019/Oct/38http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20191030-01-binder-enhttps://lists.debian.org/debian-lts-announce/2020/01/msg00013.htmlhttps://lists.debian.org/debian-lts-announce/2020/03/msg00001.htmlhttps://seclists.org/bugtraq/2019/Nov/11https://security.netapp.com/advisory/ntap-20191031-0005/https://source.android.com/security/bulletin/2019-10-01https://usn.ubuntu.com/4186-1/http://packetstormsecurity.com/files/154911/Android-Binder-Use-After-Free.htmlhttp://packetstormsecurity.com/files/155212/Slackware-Security-Advisory-Slackware-14.2-kernel-Updates.htmlhttp://packetstormsecurity.com/files/156495/Android-Binder-Use-After-Free.htmlhttp://seclists.org/fulldisclosure/2019/Oct/38http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20191030-01-binder-enhttps://lists.debian.org/debian-lts-announce/2020/01/msg00013.htmlhttps://lists.debian.org/debian-lts-announce/2020/03/msg00001.htmlhttps://seclists.org/bugtraq/2019/Nov/11https://security.netapp.com/advisory/ntap-20191031-0005/https://source.android.com/security/bulletin/2019-10-01https://usn.ubuntu.com/4186-1/https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-2215
2019-10-11
Published
2021-11-03
Added to CISA KEV
Exploited in the wild