Samsung Mobile Devices Race Condition Vulnerability (CVE-2021-25395)
Samsung mobile devices contain a race condition vulnerability within the MFC charger driver that leads to a use-after-free allowing for a write given a radio privilege is compromised.
A local attacker, with administrative privileges, can achieve full data confidentiality loss, arbitrary modification of data, complete denial of service or system unavailability. Federal agencies are required to remediate by 2023-07-20 under CISA BOD 22-01.
This is a Race Condition (CWE-362) vulnerability in Samsung Mobile Devices. A race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows local attackers to bypass signature check given a radio privilege is compromised. Exploitation requires local access, higher attack complexity, an administrative account, and no user interaction required.
Probably yes if any of these apply:
CISA added this CVE to the Known Exploited Vulnerabilities catalog on 2023-06-29 based on evidence of active exploitation in the wild. Federal agencies required to remediate by 2023-07-20.
Manual remediation steps
No tested PowerShell script for this entry yet. We’re prioritising automation based on user demand.