Samsung Mobile Devices Improper Access Control Vulnerability (CVE-2021-25337)
Samsung mobile devices contain an improper access control vulnerability in clipboard service which allows untrusted applications to read or write arbitrary files. This vulnerability was chained with CVE-2021-25369 and CVE-2021-25370.
A local attacker, without authentication, can achieve partial data exposure, partial data tampering. Federal agencies are required to remediate by 2022-11-29 under CISA BOD 22-01.
This is a Improper Privilege Management (CWE-269) vulnerability in Samsung Mobile Devices. Improper access control in clipboard service in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows untrusted applications to read or write certain local files. Exploitation requires local access, low attack complexity, no authentication required, and user interaction required.
Probably yes if any of these apply:
CISA added this CVE to the Known Exploited Vulnerabilities catalog on 2022-11-08 based on evidence of active exploitation in the wild. Federal agencies required to remediate by 2022-11-29.
Manual remediation steps
No tested PowerShell script for this entry yet. We’re prioritising automation based on user demand.