Remote Code Execution Vulnerability in Samsung Galaxy S9 GameServiceReceiver
CVE-2019-6742

10CRITICAL

Key Information:

Vendor
Samsung
Status
Vendor
CVE Published:
3 June 2019

Summary

This vulnerability permits remote attackers to execute arbitrary code on unpatched installations of the Samsung Galaxy S9. It is related to the handling of the GameServiceReceiver update mechanism, which can be exploited without any authentication. By leveraging this flaw, an attacker may run code within the context of the current process, potentially compromising the device's security and integrity.

Affected Version(s)

Galaxy S9 prior to 1.4.20.2

References

EPSS Score

19% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

MWR Labs - Georgi Geshev and Robert Miller
.