Permissions, Privileges, and Access Controls in Samsung Mobile Firmware - CVE-2021-25337

 

Permissions, Privileges, and Access Controls in Samsung Mobile Firmware - CVE-2021-25337

Published: November 10, 2022


Vulnerability identifier: #VU69225
CSH Severity: High
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-25337
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a local application to escalate privileges on the system.

The vulnerability exists due to improper access control in clipboard service. A local application can use the clipboard service to read and write arbitrary files on the device.

Note, the vulnerability is being actively exploited in the wild.


Affected software

Samsung Mobile Firmware

How to mitigate CVE-2021-25337

Install updates from vendor's website.

Samsung Mobile Firmware - update to SMR-MAR-2021

External References

Related Security Bulletins