peter bassill · operator
$ cve CVE-2019-2215 JSON

CVE-2019-2215 KEV EXPLOIT

7.8
HIGH · CVSS 3.1 · EPSS 72.1% (pctl 99)

Patch first

On CISA KEV — known exploited in the wild, due 2022-05-03.

Description

A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit this vulnerability, however exploitation does require either the installation of a malicious local application or a separate vulnerability in a network facing application.Product: AndroidAndroid ID: A-141720095

Scoring

CVSS7.8 (HIGH, v3.1)
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS72.11% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-416
On CISA KEVyes — remediate by 2022-05-03
Public exploityes
Published2019-10-11
Last modified2026-06-17

CISA KEV

NameAndroid Kernel Use-After-Free Vulnerability
Added2021-11-03
Due2022-05-03
Vendor / productAndroid / Android Kernel
Ransomware usenone reported

Affected (40)

VendorProduct
canonicalubuntu linux
debiandebian linux
googleandroid
huaweialp-al00b
huaweialp-al00b firmware
huaweialp-tl00b firmware
netappa220
netappa220 firmware
netappa320
netappa320 firmware
netappa800
netappa800 firmware
netappaff baseboard management controller
netappaff baseboard management controller firmware
netappc190
netappc190 firmware
netappcloud backup
netappdata availability services
netappfas2720
netappfas2720 firmware
netappfas2750
netappfas2750 firmware
netapph300s
netapph300s firmware
netapph410c
netapph410c firmware
netapph410s
netapph410s firmware
netapph500s
netapph500s firmware
netapph610s
netapph610s firmware
netapph700s
netapph700s firmware
netapphci management node
netappservice processor
netappsolidfire
netappsolidfire baseboard management controller
netappsolidfire baseboard management controller firmware
netappsteelstore cloud integrated storage

Public exploits

SourceTitleDate
exploit-dbAndroid Binder - Use-After-Free (Metasploit)2020-02-24
exploit-dbAndroid - Binder Driver Use-After-Free2019-10-04

References

→ the Explorer  ·  watch your stack  ·  NVD