// For flags

CVE-2014-7911

Android CVE-2014-7911 / CVE-2014-4322 Local Exploit

Severity Score

7.2
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

3
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

luni/src/main/java/java/io/ObjectInputStream.java in the java.io.ObjectInputStream implementation in Android before 5.0.0 does not verify that deserialization will result in an object that met the requirements for serialization, which allows attackers to execute arbitrary code via a crafted finalize method for a serialized object in an ArrayMap Parcel within an intent sent to system_service, as demonstrated by the finalize method of android.os.BinderProxy, aka Bug 15874291.

luni/src/main/java/java/io/ObjectInputStream.java en la implementación java.io.ObjectInputStream en Android anterior a 5.0.0 no verifica que la deserialización resultará en un objeto que reunió los requisitos para la serialización, lo que permite a atacantes ejecutar código arbitrario a través de un método de finalizar para un objeto serializado en un paquete ArrayMap dentor de un intento enviado a system_service, tal y como fue demostrado por el método de finalizar de android.os.BinderProxy, también conocido como Bug 15874291.

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2014-10-06 CVE Reserved
  • 2014-12-15 CVE Published
  • 2016-03-23 First Exploit
  • 2023-11-08 EPSS Updated
  • 2024-08-06 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-264: Permissions, Privileges, and Access Controls
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Google
Search vendor "Google"
Android
Search vendor "Google" for product "Android"
<= 4.4.4
Search vendor "Google" for product "Android" and version " <= 4.4.4"
-
Affected
Google
Search vendor "Google"
Android
Search vendor "Google" for product "Android"
1.0
Search vendor "Google" for product "Android" and version "1.0"
-
Affected
Google
Search vendor "Google"
Android
Search vendor "Google" for product "Android"
1.1
Search vendor "Google" for product "Android" and version "1.1"
-
Affected
Google
Search vendor "Google"
Android
Search vendor "Google" for product "Android"
1.5
Search vendor "Google" for product "Android" and version "1.5"
-
Affected
Google
Search vendor "Google"
Android
Search vendor "Google" for product "Android"
1.6
Search vendor "Google" for product "Android" and version "1.6"
-
Affected
Google
Search vendor "Google"
Android
Search vendor "Google" for product "Android"
2.0
Search vendor "Google" for product "Android" and version "2.0"
-
Affected
Google
Search vendor "Google"
Android
Search vendor "Google" for product "Android"
2.0.1
Search vendor "Google" for product "Android" and version "2.0.1"
-
Affected
Google
Search vendor "Google"
Android
Search vendor "Google" for product "Android"
2.1
Search vendor "Google" for product "Android" and version "2.1"
-
Affected
Google
Search vendor "Google"
Android
Search vendor "Google" for product "Android"
2.2
Search vendor "Google" for product "Android" and version "2.2"
-
Affected
Google
Search vendor "Google"
Android
Search vendor "Google" for product "Android"
2.2
Search vendor "Google" for product "Android" and version "2.2"
rev1
Affected
Google
Search vendor "Google"
Android
Search vendor "Google" for product "Android"
2.2.1
Search vendor "Google" for product "Android" and version "2.2.1"
-
Affected
Google
Search vendor "Google"
Android
Search vendor "Google" for product "Android"
2.2.2
Search vendor "Google" for product "Android" and version "2.2.2"
-
Affected
Google
Search vendor "Google"
Android
Search vendor "Google" for product "Android"
2.2.3
Search vendor "Google" for product "Android" and version "2.2.3"
-
Affected
Google
Search vendor "Google"
Android
Search vendor "Google" for product "Android"
2.3
Search vendor "Google" for product "Android" and version "2.3"
-
Affected
Google
Search vendor "Google"
Android
Search vendor "Google" for product "Android"
2.3
Search vendor "Google" for product "Android" and version "2.3"
rev1
Affected
Google
Search vendor "Google"
Android
Search vendor "Google" for product "Android"
2.3.1
Search vendor "Google" for product "Android" and version "2.3.1"
-
Affected
Google
Search vendor "Google"
Android
Search vendor "Google" for product "Android"
2.3.2
Search vendor "Google" for product "Android" and version "2.3.2"
-
Affected
Google
Search vendor "Google"
Android
Search vendor "Google" for product "Android"
2.3.3
Search vendor "Google" for product "Android" and version "2.3.3"
-
Affected
Google
Search vendor "Google"
Android
Search vendor "Google" for product "Android"
2.3.4
Search vendor "Google" for product "Android" and version "2.3.4"
-
Affected
Google
Search vendor "Google"
Android
Search vendor "Google" for product "Android"
2.3.5
Search vendor "Google" for product "Android" and version "2.3.5"
-
Affected
Google
Search vendor "Google"
Android
Search vendor "Google" for product "Android"
2.3.6
Search vendor "Google" for product "Android" and version "2.3.6"
-
Affected
Google
Search vendor "Google"
Android
Search vendor "Google" for product "Android"
2.3.7
Search vendor "Google" for product "Android" and version "2.3.7"
-
Affected
Google
Search vendor "Google"
Android
Search vendor "Google" for product "Android"
3.0
Search vendor "Google" for product "Android" and version "3.0"
-
Affected
Google
Search vendor "Google"
Android
Search vendor "Google" for product "Android"
3.1
Search vendor "Google" for product "Android" and version "3.1"
-
Affected
Google
Search vendor "Google"
Android
Search vendor "Google" for product "Android"
3.2
Search vendor "Google" for product "Android" and version "3.2"
-
Affected
Google
Search vendor "Google"
Android
Search vendor "Google" for product "Android"
3.2.1
Search vendor "Google" for product "Android" and version "3.2.1"
-
Affected
Google
Search vendor "Google"
Android
Search vendor "Google" for product "Android"
3.2.2
Search vendor "Google" for product "Android" and version "3.2.2"
-
Affected
Google
Search vendor "Google"
Android
Search vendor "Google" for product "Android"
3.2.4
Search vendor "Google" for product "Android" and version "3.2.4"
-
Affected
Google
Search vendor "Google"
Android
Search vendor "Google" for product "Android"
3.2.6
Search vendor "Google" for product "Android" and version "3.2.6"
-
Affected
Google
Search vendor "Google"
Android
Search vendor "Google" for product "Android"
4.0
Search vendor "Google" for product "Android" and version "4.0"
-
Affected
Google
Search vendor "Google"
Android
Search vendor "Google" for product "Android"
4.0.1
Search vendor "Google" for product "Android" and version "4.0.1"
-
Affected
Google
Search vendor "Google"
Android
Search vendor "Google" for product "Android"
4.0.2
Search vendor "Google" for product "Android" and version "4.0.2"
-
Affected
Google
Search vendor "Google"
Android
Search vendor "Google" for product "Android"
4.0.3
Search vendor "Google" for product "Android" and version "4.0.3"
-
Affected
Google
Search vendor "Google"
Android
Search vendor "Google" for product "Android"
4.0.4
Search vendor "Google" for product "Android" and version "4.0.4"
-
Affected
Google
Search vendor "Google"
Android
Search vendor "Google" for product "Android"
4.1
Search vendor "Google" for product "Android" and version "4.1"
-
Affected
Google
Search vendor "Google"
Android
Search vendor "Google" for product "Android"
4.1.2
Search vendor "Google" for product "Android" and version "4.1.2"
-
Affected
Google
Search vendor "Google"
Android
Search vendor "Google" for product "Android"
4.2
Search vendor "Google" for product "Android" and version "4.2"
-
Affected
Google
Search vendor "Google"
Android
Search vendor "Google" for product "Android"
4.2.1
Search vendor "Google" for product "Android" and version "4.2.1"
-
Affected
Google
Search vendor "Google"
Android
Search vendor "Google" for product "Android"
4.2.2
Search vendor "Google" for product "Android" and version "4.2.2"
-
Affected
Google
Search vendor "Google"
Android
Search vendor "Google" for product "Android"
4.3
Search vendor "Google" for product "Android" and version "4.3"
-
Affected
Google
Search vendor "Google"
Android
Search vendor "Google" for product "Android"
4.3.1
Search vendor "Google" for product "Android" and version "4.3.1"
-
Affected
Google
Search vendor "Google"
Android
Search vendor "Google" for product "Android"
4.4
Search vendor "Google" for product "Android" and version "4.4"
-
Affected
Google
Search vendor "Google"
Android
Search vendor "Google" for product "Android"
4.4.1
Search vendor "Google" for product "Android" and version "4.4.1"
-
Affected
Google
Search vendor "Google"
Android
Search vendor "Google" for product "Android"
4.4.2
Search vendor "Google" for product "Android" and version "4.4.2"
-
Affected
Google
Search vendor "Google"
Android
Search vendor "Google" for product "Android"
4.4.3
Search vendor "Google" for product "Android" and version "4.4.3"
-
Affected