Remote Code Execution Vulnerability in Samsung Galaxy S9 GameServiceReceiver
CVE-2019-6742
10CRITICAL
Summary
This vulnerability permits remote attackers to execute arbitrary code on unpatched installations of the Samsung Galaxy S9. It is related to the handling of the GameServiceReceiver update mechanism, which can be exploited without any authentication. By leveraging this flaw, an attacker may run code within the context of the current process, potentially compromising the device's security and integrity.
Affected Version(s)
Galaxy S9 prior to 1.4.20.2
References
EPSS Score
19% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
MWR Labs - Georgi Geshev and Robert Miller