Samsung Mobile Devices Improper Access Control Vulnerability (CVE-2021-25369)
Samsung mobile devices using Mali GPU contains an improper access control vulnerability in sec_log file. Exploitation of the vulnerability exposes sensitive kernel information to the userspace. This vulnerability was chained with CVE-2021-25337 and CVE-2021-25370.
A local attacker, without authentication, can achieve full data confidentiality loss. Federal agencies are required to remediate by 2022-11-29 under CISA BOD 22-01.
This is a Information Disclosure (CWE-200) vulnerability in Samsung Mobile Devices. An improper access control vulnerability in sec_log file prior to SMR MAR-2021 Release 1 exposes sensitive kernel information to userspace. Exploitation requires local access, low attack complexity, no authentication required, and no user interaction required.
Probably yes if any of these apply:
CISA added this CVE to the Known Exploited Vulnerabilities catalog on 2022-11-08 based on evidence of active exploitation in the wild. Federal agencies required to remediate by 2022-11-29.
Manual remediation steps
No tested PowerShell script for this entry yet. We’re prioritising automation based on user demand.