EXPOSURES › CVE-2021-25487
CVE-2021-25487
HIGH ⌖ ON CISA KEV · EXPLOITEDSamsung mobile devices contained an out-of-bounds read vulnerability allowing remote code execution, and it's currently being exploited in the wild.
A lack of boundary checking in the modem interface driver of Samsung mobile devices allowed for remote code execution via an out-of-bounds read. DIB organizations using these devices face potential compromise and must immediately patch to mitigate risk and maintain CMMC compliance. Verify patching status and consider network segmentation to limit potential impact.
Shame score — The vulnerability's exploitation in the wild and potential for remote code execution demonstrates a significant failure in Samsung's secure coding practices and risk management.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Samsung mobile devices contain an out-of-bounds read vulnerability within the modem interface driver due to a lack of boundary checking of a buffer in set_skb_priv(), leading to remote code execution by dereference of an invalid function pointer.