Skip to content
COOEY

EXPOSURES › CVE-2021-25371

CVE-2021-25371

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2023-06-29 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-25371 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 exploited-in-wildunpatchedrce

Samsung mobile devices have an unspecified vulnerability allowing arbitrary code execution via ELF library loading within the DSP driver, and it's currently being exploited in the wild.

A vulnerability in Samsung's DSP driver allows attackers to load arbitrary ELF libraries, enabling remote code execution. DIB organizations using Samsung mobile devices must immediately assess their risk and apply available patches, as this vulnerability is actively exploited. Failure to do so could lead to data compromise and non-compliance with NIST 800-171.

Shame score — The vulnerability's exploitation in the wild and potential for remote code execution demonstrate a significant security oversight by Samsung, impacting device security and potentially DIB data.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Samsung mobile devices contain an unspecified vulnerability within DSP driver that allows attackers to load ELF libraries inside DSP.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.