CVE-2019-2215 KEV EXPLOIT
7.8
HIGH · CVSS 3.1 · EPSS 72.1% (pctl 99)
Patch first
On CISA KEV — known exploited in the wild, due 2022-05-03.
Description
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit this vulnerability, however exploitation does require either the installation of a malicious local application or a separate vulnerability in a network facing application.Product: AndroidAndroid ID: A-141720095
Scoring
| CVSS | 7.8 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 72.11% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-416 |
| On CISA KEV | yes — remediate by 2022-05-03 |
| Public exploit | yes |
| Published | 2019-10-11 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | Android Kernel Use-After-Free Vulnerability |
|---|---|
| Added | 2021-11-03 |
| Due | 2022-05-03 |
| Vendor / product | Android / Android Kernel |
| Ransomware use | none reported |
Affected (40)
| Vendor | Product |
|---|---|
| canonical | ubuntu linux |
| debian | debian linux |
| android | |
| huawei | alp-al00b |
| huawei | alp-al00b firmware |
| huawei | alp-tl00b firmware |
| netapp | a220 |
| netapp | a220 firmware |
| netapp | a320 |
| netapp | a320 firmware |
| netapp | a800 |
| netapp | a800 firmware |
| netapp | aff baseboard management controller |
| netapp | aff baseboard management controller firmware |
| netapp | c190 |
| netapp | c190 firmware |
| netapp | cloud backup |
| netapp | data availability services |
| netapp | fas2720 |
| netapp | fas2720 firmware |
| netapp | fas2750 |
| netapp | fas2750 firmware |
| netapp | h300s |
| netapp | h300s firmware |
| netapp | h410c |
| netapp | h410c firmware |
| netapp | h410s |
| netapp | h410s firmware |
| netapp | h500s |
| netapp | h500s firmware |
| netapp | h610s |
| netapp | h610s firmware |
| netapp | h700s |
| netapp | h700s firmware |
| netapp | hci management node |
| netapp | service processor |
| netapp | solidfire |
| netapp | solidfire baseboard management controller |
| netapp | solidfire baseboard management controller firmware |
| netapp | steelstore cloud integrated storage |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Android Binder - Use-After-Free (Metasploit) | 2020-02-24 |
| exploit-db | Android - Binder Driver Use-After-Free | 2019-10-04 |
References
- http://packetstormsecurity.com/files/154911/Android-Binder-Use-After-Free.html
- http://packetstormsecurity.com/files/155212/Slackware-Security-Advisory-Slackware-14.2-kernel-Updates.html
- http://packetstormsecurity.com/files/156495/Android-Binder-Use-After-Free.html
- http://seclists.org/fulldisclosure/2019/Oct/38
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20191030-01-binder-en
- https://lists.debian.org/debian-lts-announce/2020/01/msg00013.html
- https://lists.debian.org/debian-lts-announce/2020/03/msg00001.html
- https://seclists.org/bugtraq/2019/Nov/11
- https://security.netapp.com/advisory/ntap-20191031-0005/
- https://source.android.com/security/bulletin/2019-10-01
- https://usn.ubuntu.com/4186-1/
- http://packetstormsecurity.com/files/154911/Android-Binder-Use-After-Free.html
- http://packetstormsecurity.com/files/155212/Slackware-Security-Advisory-Slackware-14.2-kernel-Updates.html
- http://packetstormsecurity.com/files/156495/Android-Binder-Use-After-Free.html
- http://seclists.org/fulldisclosure/2019/Oct/38
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20191030-01-binder-en
- https://lists.debian.org/debian-lts-announce/2020/01/msg00013.html
- https://lists.debian.org/debian-lts-announce/2020/03/msg00001.html
- https://seclists.org/bugtraq/2019/Nov/11
- https://security.netapp.com/advisory/ntap-20191031-0005/
→ the Explorer · watch your stack · NVD