ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

WhatsApp RCE flaw can be exploited by sending malicious MP4 files

criticalVulnerability exploited in the wildimportance 60CVE-2019-11931CVE-2019-3568

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2019-11931
A stack-based buffer overflow could be triggered in WhatsApp by sending a specially crafted MP4 file to a WhatsApp user.

A stack-based buffer overflow could be triggered in WhatsApp by sending a specially crafted MP4 file to a WhatsApp user. The issue was present in parsing the elementary stream metadata of an MP4 file and could result in a DoS or RCE. This affects Android versions prior to 2.19.274, iOS versions prior to 2.19.100, Enterprise Client versions prior to 2.25.3, Business for Android versions prior to 2.19.104 and Business for iOS versions prior to 2.19.100.

NVD description · AI analysis pending
7.81%
  • whatsapp whatsapp
  • whatsapp whatsapp business
  • whatsapp whatsapp enterprise client
CVE-2019-3568
Buffer Overflow RCE in WhatsApp VoIP Stack via Crafted RTCP Packets

A buffer overflow (CWE-122) in the VoIP telephony stack of WhatsApp allowed a remote attacker to achieve remote code execution on a target device by sending a specially crafted series of RTCP packets to the victim's phone number. Because the flaw resided in the call-handling stack of the core app, an attacker who could reach the target's phone number over the network could gain arbitrary code execution on the device. All WhatsApp users at the time of disclosure were potentially exposed, since the vulnerable component shipped in the mainstream Meta Platforms (then Facebook) product rather than an optional add-on. The vulnerability was added to CISA's Known Exploited Vulnerability catalog on 2022-04-19, indicating confirmed real-world exploitation, and its EPSS score of 39.2% (99th percentile) signals a high likelihood of continued exploitation; no public proof-of-concept is known. It was remediated in vendor updates issued in 2019 and is widely associated with targeted espionage use (notably Pegasus spyware deployments).

Do: Update WhatsApp on all mobile devices to the latest vendor release, per the CISA KEV required action; inventory your mobile fleet for outdated 2019-era builds and verify current app versions. Prioritize high-value targets (executives, journalists, government personnel) given the vulnerability's confirmed in-the-wild exploitation in espionage campaigns. No public PoC is known, but the flaw is remotely exploitable via network packets to a phone number, so treat patching as urgent.

9.830% KEV
  • Meta Platforms WhatsApp
mass≈1.5–2 billion users (effectively the entire global WhatsApp user base at the time of disclosure)
Full article313 words · extracted from helpnetsecurity.com · click to collapse

Facebook has patched a critical vulnerability (CVE-2019-11931) affecting various versions of its popular WhatsApp Messenger app and is urging users to update as soon as possible.

CVE-2019-11931

About the patched flaw (CVE-2019-11931)

CVE-2019-11931 is a stack-based buffer overflow vulnerability that could be triggered in WhatsApp by sending a specially crafted MP4 file to a WhatsApp user.

“The issue was present in parsing the elementary stream metadata of an MP4 file and could result in a DoS [denial of service] or RCE [remote code execution],” Facebook explained in a (light) security advisory.

The vulnerability affects:

  • Android versions prior to 2.19.274
  • iOS versions prior to 2.19.100
  • Enterprise Client versions prior to 2.25.3
  • Windows Phone versions before and including 2.18.368
  • Business for Android versions prior to 2.19.104, and
  • Business for iOS versions prior to 2.19.100.

There is no indication that the flaw is being actively exploited. Facebook also doesn’t specify whether any user interaction is required for exploitation, so assume that it’s not.

Upgrade today

Users would do well to upgrade to the newest offered versions, especially if their WhatsApp is configured to automatically download photo, video or audio files sent to them.

This latest issue brings to mind CVE-2019-3568, the buffer overflow vulnerability in WhatsApp VoIP stack that allowed remote code execution via specially crafted series of SRTCP packets sent to a target phone number.

Publicly revealed in May 2019, it had been exploited in extremely targeted attacks to deliver the Pegasus mobile spyware developed by Israeli company NSO Group.

Less than a month ago, Facebook filed a suit against NSO Group, saying that it exploited CVE-2019-3568 to infect over 1,400 phones with malware.

Facebook says NSO Group violated the U.S. Computer Fraud and Abuse Act and wants a U.S. court to bar the company from using Facebook and WhatsApp services and systems and to pay for the damage it has caused to Facebook.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2019/11/18/cve-2019-11931/