⚠ Actively exploited
Added to CISA KEV on 2022-11-08. Federal agencies required to patch by 2022-11-29. Required action: Apply updates per vendor instructions..
Severity
7.1HIGHNVD
CNA4.4VulnCheck4.4
EPSS
1.1%
top 21.70%
CISA KEV
KEV
Added 2022-11-08
Due 2022-11-29
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedMar 4
KEV addedNov 8
KEV dueNov 29
CISA Required Action: Apply updates per vendor instructions.

Description

Improper access control in clipboard service in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows untrusted applications to read or write certain local files.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:NExploitability: 1.8 | Impact: 5.2

Affected Packages2 packages

CVEListV5samsung_mobile/samsung_mobile_devicesSelected P(9.0), Q(10.0), R(11.0)SMR Mar-2021 Release 1
NVDsamsung/android10.0, 11.0, 9.0+2

🔴Vulnerability Details

7
Project0
A Very Powerful Clipboard: Analysis of a Samsung in-the-wild exploit chain - Project Zero2022-11-01
GHSA
GHSA-7x25-8cjm-2rj9: Improper access control in clipboard service in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows untrusted applications to read or write2022-05-24
CVEList
CVE-2021-25337: Improper access control in clipboard service in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows untrusted applications to read or write2021-03-04
VulnCheck
Samsung Mobile Devices Memory Corruption Vulnerability2021
VulnCheck
Samsung Mobile Devices Improper Access Control Vulnerability2021

📋Vendor Advisories

3
CISA
Samsung Mobile Devices Improper Access Control Vulnerability2022-11-08
CISA
Samsung Mobile Devices Improper Access Control Vulnerability2022-11-08
CISA
Samsung Mobile Devices Memory Corruption Vulnerability2022-11-08
CVE-2021-25337 — Improper Privilege Management | cvebase