EXPOSURES › CVE-2021-25372
CVE-2021-25372
HIGH ⌖ ON CISA KEV · EXPLOITEDSamsung mobile devices had an improperly checked boundary in their DSP driver, leading to out-of-bounds memory access and active exploitation in the wild.
An improper boundary check in Samsung's DSP driver allowed for out-of-bounds memory access, actively exploited and linked to KEV. DIB organizations using Samsung mobile devices must immediately patch to prevent potential data compromise and compliance failures (NIST 800-171 controls 3.1.1, 3.1.2). Verify patching status and consider device restrictions.
Shame score — The vulnerability's active exploitation demonstrates a failure to implement basic secure coding practices, and the widespread use of Samsung devices amplifies the potential impact.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Samsung mobile devices contain an improper boundary check vulnerability within DSP driver that allows for out-of-bounds memory access.