Skip to content
COOEY

EXPOSURES › CVE-2021-1905

CVE-2021-1905

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-1905 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 exploited-in-wildunpatchedransomwarerce

Qualcomm chipsets suffered a use-after-free vulnerability that was actively exploited in the wild, enabling remote code execution and privilege escalation.

A use-after-free flaw in Qualcomm chipsets allowed attackers to execute arbitrary code and escalate privileges, directly impacting CMMC/NIST 800-171 controls for system integrity and access control. DIB organizations must ensure all Qualcomm hardware is patched to the 2021-05-05 security level or later, as the vulnerability was actively exploited in the wild and linked to ransomware campaigns.

Shame score — The vulnerability was actively exploited in the wild and linked to ransomware campaigns, demonstrating severe negligence in patching known, high-severity flaws in critical hardware.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Multiple Qualcomm Chipsets contain a use after free vulnerability due to improper handling of memory mapping of multiple processes simultaneously.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.60
Qualcomm's use-after-free flaw in multiple chipsets was a significant security oversight, though the provided source lacks explicit sentiment or vendor response details, resulting in a neutral-to-nega
cooey ↗ severe-fallout +0.00
Neutral factual disclosure; no sentiment or vendor response expressed in the provided text.
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.