⚠ Actively exploited
Added to CISA KEV on 2022-11-08. Federal agencies required to patch by 2022-11-29. Required action: Apply updates per vendor instructions..
CVE-2021-25337 — Improper Privilege Management in Mobile Devices
Severity
7.1HIGHNVD
CNA4.4VulnCheck4.4
EPSS
1.1%
top 21.70%
CISA KEV
KEV
Added 2022-11-08
Due 2022-11-29
Exploit
Exploited in wild
Active exploitation observed
Affected products
Timeline
PublishedMar 4
KEV addedNov 8
KEV dueNov 29
CISA Required Action: Apply updates per vendor instructions.
Description
Improper access control in clipboard service in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows untrusted applications to read or write certain local files.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:NExploitability: 1.8 | Impact: 5.2
Affected Packages2 packages
▶CVEListV5samsung_mobile/samsung_mobile_devicesSelected P(9.0), Q(10.0), R(11.0) — SMR Mar-2021 Release 1
🔴Vulnerability Details
7Project0▶
A Very Powerful Clipboard: Analysis of a Samsung in-the-wild exploit chain - Project Zero↗2022-11-01
GHSA▶
GHSA-7x25-8cjm-2rj9: Improper access control in clipboard service in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows untrusted applications to read or write↗2022-05-24
CVEList▶
CVE-2021-25337: Improper access control in clipboard service in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows untrusted applications to read or write↗2021-03-04