logo

CVE-2021-25337 - Samsung Mobile Devices Improper Access Control Vulnerability

Project:Samsung

Product:Mobile Devices

Date Added:2022-11-08Due Date:2022-11-29

Vulnerability Name

Samsung Mobile Devices Improper Access Control Vulnerability

Description

Samsung mobile devices contain an improper access control vulnerability in clipboard service which allows untrusted applications to read or write arbitrary files. This vulnerability was chained with CVE-2021-25369 and CVE-2021-25370.

Known To Be Used in Ransomware Campaigns?

Unknown

Action

Apply updates per vendor instructions.

Additional Notes

https://security.samsungmobile.com/securityUpdate.smsb

https://nvd.nist.gov/vuln/detail/CVE-2021-25337