ZeroHour

CVE-2019-2215

KEV PoC ×2mass1

Use-After-Free Privilege Escalation in Android Kernel (CVE-2019-2215)

CISA: Android Kernel Use-After-Free Vulnerability

CVSS 3.1
7.8 high
EPSS
72%p99
Published
()
KEV added
AI analysis

CVE-2019-2215 is a use-after-free flaw (CWE-416) in the Android kernel's binder.c IPC driver that allows privilege escalation from an application to the Linux kernel. Exploitation requires no user interaction, but an attacker must either run a malicious local application or chain the bug with a vulnerability in a network-facing application. Successful exploitation yields kernel-level code execution, effectively rooting the device and giving the attacker full control over apps, data, and communications. Affected parties include Android devices with unpatched kernels (reporting at the time indicated most Android phones were affected), plus products shipping affected Android kernel code, including Google Android, Debian/Ubuntu builds, and NetApp and Huawei offerings. The flaw was publicly disclosed and patched in Android's October 2019 security updates, public proof-of-concept exploits exist, and it is listed in CISA's Known Exploited Vulnerabilities catalog with a high (72.1%) EPSS probability of exploitation; headlines confirm in-the-wild use, including a Google Play app that leveraged it to deliver spyware.

What to do: Apply vendor-supplied updates per CISA's required action — for phones and tablets, ensure the device is on the October 2019 Android security patch level or later (check Settings > About phone > Android security patch level) and patch via MDM across your fleet; NetApp, Huawei, Debian, and Ubuntu customers should install their vendors' corresponding kernel updates. Because this is a local privilege escalation with no user interaction required, also patch any network-facing applications that could be chained with it, and hunt for signs of exploitation such as unexpected root or unknown sideloaded/rooting apps on managed devices.

Affected
google android (Android kernel, binder.c)
huawei android (Android-based devices)
debian linux (Android kernel code)
canonical ubuntu linux (Android kernel code)
netapp cloud backup
netapp data availability services
netapp hci management node
netapp service processor
netapp solidfire
netapp steelstore cloud integrated storage
netapp solidfire baseboard management controller firmware
netapp aff baseboard management controller firmware
Estimated exposure
massbillions of devices — on the order of 2–3 billion Android devices running unpatched kernels at the time of disclosure (contemporaneous reporting described it… — Android holds the majority of global smartphone market share (roughly 70%+, translating to billions of active devices), and the CISA-affected product is the Android kernel itself, so nearly all Android devices predating the October 2019…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit this vulnerability, however exploitation does require either the installation of a malicious local application or a separate vulnerability in a network facing application.Product: AndroidAndroid ID: A-141720095

CISA Known Exploited Vulnerability
Affected
Android Android Kernel
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
googledebiancanonicalnetapphuawei
Products
android, debian linux, ubuntu linux, cloud backup, data availability services, hci management node, service processor, solidfire, steelstore cloud integrated storage, solidfire baseboard management controller firmware, aff baseboard management controller firmware, a320 firmware
Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news