CVE-2019-6742

CWE-3583 documents3 sources
Severity
9.8CRITICAL
EPSS
19.2%
top 4.64%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 3
Latest updateMay 24

Description

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Samsung Galaxy S9 prior to 1.4.20.2. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the GameServiceReceiver update mechanism. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-7477.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages2 packages

CVEListV5samsung/galaxy_s9prior to 1.4.20.2

🔴Vulnerability Details

2
GHSA
GHSA-q778-9mxh-6vxg: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Samsung Galaxy S9 prior to 12022-05-24
CVEList
CVE-2019-6742: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Samsung Galaxy S9 prior to 12019-06-03
CVE-2019-6742 (CRITICAL CVSS 9.8) | This vulnerability allows remote at | cvebase.io