Permissions, Privileges, and Access Controls in Samsung Mobile Firmware - CVE-2021-25337
Published: November 10, 2022
Vulnerability identifier: #VU69225
CSH Severity: High
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-25337
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability:
The vulnerability is being exploited in the wild
Vulnerability details
The vulnerability allows a local application to escalate privileges on the system.
The vulnerability exists due to improper access control in clipboard service. A local application can use the clipboard service to read and write arbitrary files on the device.
Note, the vulnerability is being actively exploited in the wild.
Affected software
Samsung Mobile Firmware
How to mitigate CVE-2021-25337
Install updates from vendor's website.
Samsung Mobile Firmware - update to SMR-MAR-2021