CRITICAL🇵🇱 Wersja polska

CVE-2019-6742

CVSS 9.8v3.1pub. 2019-06-03upd. 2024-11-21

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Samsung Galaxy S9 prior to 1.4.20.2. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the GameServiceReceiver update mechanism. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-7477.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Samsung Galaxy S9

    HW
    Samsung
    all versions
  • Samsung Galaxy S9 Firmware

    OS
    Samsung
    < 1.4.20.2
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2019-6741CRITICAL9.3PL ✓same product

RCE w captive portal Samsung Galaxy S9 — przekierowanie HTML

CVE-2019-6740HIGH8.8same product

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Samsung Ga...

CVE-2019-6744MEDIUM4.3same product

This vulnerability allows local attackers to disclose sensitive information on affected installations of Samsu...

CVE-2018-21073LOW2.4same product

Problem odkryto na urządzeniach mobilnych Samsung z systemem N(7.x) i O(8.0) (Galaxy S9+, Galaxy S9, Galaxy S8...

CVE-2025-4632CRITICAL9.8⚠ KEVPL ✓same vendor

Path Traversal w Samsung MagicINFO 9 Server — zapis plików jako SYSTEM