Back to overview

CVE-2019-6742

CRITICAL
10.0
CVSS 3.0
Description
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Samsung Galaxy S9 prior to 1.4.20.2. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the GameServiceReceiver update mechanism. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-7477.

Metadata

CVE ID
CVE-2019-6742
State
PUBLISHED
Assigner
zdi
Reserved
2019-01-24 00:00 UTC
Published
2019-06-03 18:15 UTC
Last updated
2024-08-04 20:31 UTC
Primary CWE
CWE-358
CWE-358: Improperly Implemented Security Check for Standard
Vendor / Product
Samsung / Galaxy S9
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Affected products (1)
VendorProductPlatformVersions
Samsung Galaxy S9 prior to 1.4.20.2
Weakness (CWE)
CWESourceDescription
CWE-358 cna CWE-358: Improperly Implemented Security Check for Standard
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 3.0 cna CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Back to overview