EXPOSURES › CVE-2021-1905
CVE-2021-1905
HIGH ⌖ ON CISA KEV · EXPLOITEDQualcomm chipsets suffered a use-after-free vulnerability that was actively exploited in the wild, enabling remote code execution and privilege escalation.
A use-after-free flaw in Qualcomm chipsets allowed attackers to execute arbitrary code and escalate privileges, directly impacting CMMC/NIST 800-171 controls for system integrity and access control. DIB organizations must ensure all Qualcomm hardware is patched to the 2021-05-05 security level or later, as the vulnerability was actively exploited in the wild and linked to ransomware campaigns.
Shame score — The vulnerability was actively exploited in the wild and linked to ransomware campaigns, demonstrating severe negligence in patching known, high-severity flaws in critical hardware.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Multiple Qualcomm Chipsets contain a use after free vulnerability due to improper handling of memory mapping of multiple processes simultaneously.