CVE-2022-22265
Samsung Mobile Devices Use-After-Free Vulnerability
Severity Score
7.8
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
Yes
*KEV
Decision
-
*SSVC
Descriptions
An improper check or handling of exceptional conditions in NPU driver prior to SMR Jan-2022 Release 1 allows arbitrary memory write and code execution.
Una comprobación o administración inapropiada de condiciones excepcionales en el controlador de la NPU versiones anteriores a 1 de SMR Jan-2022, permite una escritura arbitraria en memoria y una ejecución de código
Samsung devices with selected Exynos chipsets contain a use-after-free vulnerability that allows malicious memory write and code execution.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2021-12-29 CVE Reserved
- 2022-01-07 CVE Published
- 2023-09-18 Exploited in Wild
- 2023-09-19 EPSS Updated
- 2023-10-09 KEV Due Date
- 2024-08-03 CVE Updated
- ---------- First Exploit
CWE
- CWE-703: Improper Check or Handling of Exceptional Conditions
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://security.samsungmobile.com/securityUpdate.smsb?year=2022&month=1 | 2023-06-27 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Google Search vendor "Google" | Android Search vendor "Google" for product "Android" | 9.0 Search vendor "Google" for product "Android" and version "9.0" | - |
Affected
| in | Samsung Search vendor "Samsung" | Exynos Search vendor "Samsung" for product "Exynos" | - | - |
Safe
|
Google Search vendor "Google" | Android Search vendor "Google" for product "Android" | 10.0 Search vendor "Google" for product "Android" and version "10.0" | - |
Affected
| in | Samsung Search vendor "Samsung" | Exynos Search vendor "Samsung" for product "Exynos" | - | - |
Safe
|
Google Search vendor "Google" | Android Search vendor "Google" for product "Android" | 11.0 Search vendor "Google" for product "Android" and version "11.0" | - |
Affected
| in | Samsung Search vendor "Samsung" | Exynos Search vendor "Samsung" for product "Exynos" | - | - |
Safe
|
Google Search vendor "Google" | Android Search vendor "Google" for product "Android" | 12.0 Search vendor "Google" for product "Android" and version "12.0" | - |
Affected
| in | Samsung Search vendor "Samsung" | Exynos Search vendor "Samsung" for product "Exynos" | - | - |
Safe
|