CVE-2021-25397
6.8MEDIUMAn improper access control vulnerability in TelephonyUI prior to SMR MAY-2021 Release 1 allows local attackers to write arbitrary files of telephony process via untrusted applications.
Published: 6/11/2021Updated: 11/21/2024
Description
An improper access control vulnerability in TelephonyUI prior to SMR MAY-2021 Release 1 allows local attackers to write arbitrary files of telephony process via untrusted applications.
AI AnalysisPowered by AI
Affected Products
googleandroid
9.0
googleandroid
10.0
googleandroid
11.0
References
- https://blog.oversecured.com/Two-weeks-of-securing-Samsung-devices-Part-1/ExploitThird Party Advisory
- https://security.samsungmobile.com/securityUpdate.smsb?year=2021&month=5Vendor Advisory
- https://blog.oversecured.com/Two-weeks-of-securing-Samsung-devices-Part-1/ExploitThird Party Advisory
- https://security.samsungmobile.com/securityUpdate.smsb?year=2021&month=5Vendor Advisory