ZeroHour

CVE-2021-25371

KEVmass

Arbitrary ELF library loading flaw in Samsung mobile DSP driver (CVE-2021-25371)

CISA: Samsung Mobile Devices Unspecified Vulnerability

CVSS 3.1
6.7 medium
EPSS
<1%p55
Published
()
KEV added
AI analysis

CVE-2021-25371 is a vulnerability in the Digital Signal Processor (DSP) driver on Samsung mobile devices that, prior to the Samsung Mobile Security Release (SMR) Mar-2021 Release 1, allows attackers to load arbitrary ELF libraries inside the DSP. It is triggered locally, with the CVSS vector (AV:L, PR:H) indicating the attacker must already have local access with high privileges on the device. Successful exploitation lets the attacker run arbitrary library code within the DSP subsystem, with high impact on confidentiality, integrity, and availability. All Samsung mobile devices whose DSP driver has not been updated with the SMR Mar-2021 Release 1 (or later) are affected. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2023-06-29, confirming active exploitation in the wild, though ransomware use is listed as unknown.

What to do: Update affected Samsung devices to the SMR Mar-2021 Release 1 or any later Samsung mobile security release via Settings > Software update, and verify the device's Android security patch level is March 2021 or newer. Organizations subject to CISA's KEV requirements must apply the vendor update, or discontinue use of unpatched devices, per the catalog's required action.

Affected
Samsung Mobile Devices (Android)DSP driver in all Samsung mobile devices prior to SMR Mar-2021 Release 1
Estimated exposure
massplausibly hundreds of millions of Samsung Android devices (all handsets without the Mar-2021 SMR or later security patch) — Samsung is the world's largest Android OEM with hundreds of millions of active devices, and every device not yet running the March 2021 (or later) Samsung security release falls in the affected range, though the share actually patched is…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability in DSP driver prior to SMR Mar-2021 Release 1 allows attackers load arbitrary ELF libraries inside DSP.

CISA Known Exploited Vulnerability
Affected
Samsung Mobile Devices
Required action
Apply updates per vendor instructions or discontinue use of the product if updates are unavailable
Due date
Ransomware use
Unknown
Vendors
samsung
Products
android
Weakness
CWE-912
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news