Memory Corruption in Samsung S7 Edge Due to Malformed WAP Push Message
CVE-2018-10751
5.3MEDIUM
Key Information:
- Vendor
Samsung
- Status
- Vendor
- CVE Published:
- 29 May 2018
Badges
๐พ Exploit Exists๐ก Public PoC๐ฃ EPSS 14%
What is CVE-2018-10751?
A malformed OMACP WAP push message can lead to memory corruption on the Samsung Galaxy S7 Edge. This issue arises from an integer overflow that occurs during the memory allocation process for the String Extension portion of the WbXml payload, potentially allowing attackers to exploit this vulnerability for unauthorized access to system resources.
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
EPSS Score
14% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved