The kernel in Samsung Galaxy S2, Galaxy Note 2, MEIZU...
Vulnerability Description
The kernel in Samsung Galaxy S2, Galaxy Note 2, MEIZU MX, and possibly other Android devices, when running an Exynos 4210 or 4412 processor, uses weak permissions (0666) for /dev/exynos-mem, which allows attackers to read or write arbitrary physical memory and gain privileges via a crafted application, as demonstrated by ExynosAbuse.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2012-6422
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.securityweek.com/new-vulnerability-exposed-samsungs-android-devices
- http://project-voodoo.org/articles/instant-fix-app-for-exynos-mem-abuse-vulnerability-no-root-required-reversible
- http://forum.xda-developers.com/showthread.php?p=35469999
- http://arstechnica.com/security/2012/12/developer-warns-of-critical-vulnerability-in-many-samsung-smartphones/
- http://forum.xda-developers.com/showthread.php?t=2051290
- http://www.sammobile.com/2012/12/16/major-vulnerability-found-on-exynos-4-devices/
- http://osvdb.org/88467
Affected Vendor
meizu
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.