Skip to content
COOEY

EXPOSURES › CVE-2019-2215

CVE-2019-2215

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2019-2215 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 78/100 exploited-in-wildunpatchedprivilege-escalationrce

A use-after-free vulnerability in the Android kernel allowed privilege escalation from an app to the Linux kernel, often chained with other CVEs to gain full control.

This kernel-level flaw in binder.c enabled attackers to escalate privileges from a malicious app to the Linux kernel, potentially achieving root access. DIB organizations must ensure all mobile devices and endpoints run patched OS versions, as this class of vulnerability is frequently chained with others to bypass security controls. The failure highlights the risk of relying on unpatched mobile devices for sensitive operations.

Shame score — A kernel-level privilege escalation flaw that was actively exploited in the wild and chained with other vulnerabilities to achieve full device control, indicating a severe and avoidable security gap.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Android Kernel contains a use-after-free vulnerability in binder.c that allows for privilege escalation from an application to the Linux Kernel. This vulnerability was observed chained with CVE-2020-0041 and CVE-2020-0069 under exploit chain "AbstractEmu."

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.60
Android's kernel privilege escalation flaw was widely recognized as critical, especially when chained with other exploits, though vendor response details are absent from the provided sources.
cooey ↗ severe-fallout -0.80
Critical kernel flaw allowing privilege escalation, observed in exploit chains, indicating severe impact.
"Android Kernel contains a use-after-free vulnerability in binder.c that allows for privilege escalation from an application to the Linux Kernel. This vulnerability was observed chained with CVE-2020-0041 and CVE-2020-0069 under exploit chain 'AbstractEmu.'"
CISA ↗ severe-fallout +0.00
No direct mention of CVE-2019-2215; source is generic CISA homepage.
www.cvefind.com ↗ severe-fallout +0.00
Generic CVE database page; no specific sentiment toward Android.
app.opencve.io ↗ severe-fallout +0.00
Generic CVE database page; no specific sentiment toward Android.
sec.cloudapps.cisco.com ↗ severe-fallout +0.00
Cisco advisory unrelated to Android; no sentiment toward Android.
NVD ↗ severe-fallout +0.00
NVD page unrelated to Android; no sentiment toward Android.
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.