Skip to content
COOEY

EXPOSURES › CVE-2019-3568

CVE-2019-3568

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-04-19 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2019-3568 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 78/100 rceexploited-in-wildunpatched

A buffer overflow in WhatsApp's VOIP stack allowed remote code execution via crafted RTCP packets.

The vulnerability in WhatsApp's VOIP stack enabled attackers to execute arbitrary code remotely by sending specially crafted RTCP packets, bypassing end-to-end encryption protections. DIB organizations must ensure their communication tools are patched against known CVEs, as this exploit was actively exploited in the wild and highlights systemic weaknesses in input validation and patching cycles. Organizations should prioritize updating their communication infrastructure and monitoring for similar vulnerabilities in their supply chain.

Shame score — A high-severity RCE vulnerability in a widely used communication tool was actively exploited in the wild, indicating avoidable gaps in patching and input validation that could compromise sensitive data and systems.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

A buffer overflow vulnerability in WhatsApp VOIP stack allowed remote code execution via specially crafted series of RTCP packets sent to a target phone number.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.