#VU35165 Use-after-free in Google Android - CVE-2019-2215

 

#VU35165 Use-after-free in Google Android - CVE-2019-2215

Published: October 11, 2019 / Updated: April 19, 2024


Vulnerability identifier: #VU35165
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:A/U:Clear
CVE-ID: CVE-2019-2215
CWE-ID: CWE-416
Exploitation vector: Local access
Exploit availability: The vulnerability is being exploited in the wild
Vulnerable software:
Google Android
Software vendor:
Google

Description

The vulnerability allows a local authenticated user to execute arbitrary code.

A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit this vulnerability, however exploitation does require either the installation of a malicious local application or a separate vulnerability in a network facing application.Product: AndroidAndroid ID: A-141720095


Remediation

Install update from vendor's website.

External links