CVE-2016-9567
Last modified
CVE-2016-9567 is a vulnerability of currently unknown severity. The mDNIe system service on Samsung Mobile S7 devices with M(6.0) software does not properly restrict setmDNIeScreenCurtain API calls, enabling attackers to control a device's screen. This can be exploited via a crafted application to eavesdrop after phone shutdown or record a conversation. EPSS estimates a 0.94% chance of exploitation in the next 30 days.
Description
The mDNIe system service on Samsung Mobile S7 devices with M(6.0) software does not properly restrict setmDNIeScreenCurtain API calls, enabling attackers to control a device's screen. This can be exploited via a crafted application to eavesdrop after phone shutdown or record a conversation. The Samsung ID is SVE-2016-6343.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Samsung | Samsung Mobile | 6.0 |
References
- http://www.securityfocus.com/bid/94494Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/94494Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-9567?
How severe is CVE-2016-9567?
How do I fix CVE-2016-9567?
Are you affected by CVE-2016-9567?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
