Skip to content
COOEY

EXPOSURES › CVE-2021-25337

CVE-2021-25337

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-11-08 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-25337 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 exploited-in-wildunpatched

Samsung mobile devices had unpatched clipboard service access control vulnerability allowing untrusted apps to read or write files

Samsung mobile devices had unpatched clipboard service access control vulnerability allowing untrusted apps to read or write files, linked with other vulnerabilities and actively exploited in the wild.

Shame score — Improper access control in clipboard service enabling untrusted applications to access files, actively exploited in the wild.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Samsung mobile devices contain an improper access control vulnerability in clipboard service which allows untrusted applications to read or write arbitrary files. This vulnerability was chained with CVE-2021-25369 and CVE-2021-25370.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.