CVE-2019-9345
Last modified
CVE-2019-9345 is a vulnerability of currently unknown severity. In the Android kernel in sdcardfs there is a possible violation of the separation of data between profiles due to shared mapping of obb files. This could lead to local escalation of privilege with User execution privileges needed. EPSS estimates a 0.20% chance of exploitation in the next 30 days.
Description
In the Android kernel in sdcardfs there is a possible violation of the separation of data between profiles due to shared mapping of obb files. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Android | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-9345?
How severe is CVE-2019-9345?
How do I fix CVE-2019-9345?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-9337In libavc there is a possible information disclosure due to …6.5
- CVE-2019-9338In libavc there is a possible information disclosure due to …6.5
- CVE-2019-9341In Bluetooth, there is a possible out of bounds read due to …7.5
- CVE-2019-9342In Bluetooth, there is a possible out of bounds read due to …7.5
- CVE-2019-9343In Bluetooth, there is a possible out of bounds read due to …7.5
- CVE-2019-9344In NFC server, there is a possible out of bounds read due to…5
- CVE-2019-9346In libstagefright, there is a possible out of bounds write d…8.8
- CVE-2019-9347In the m4v_h263 codec, there is a possible out of bounds rea…5.5
- CVE-2019-9348In libstagefright, there is a possible resource exhaustion d…6.5
- CVE-2019-9349In libstagefright, there is a possible resource exhaustion d…6.5
- CVE-2019-9350In Keymaster, there is a possible EoP due to a use after fre…7.8
- CVE-2019-9351In SyncStatusObserver, there is a possible bypass for operat…3.3
Are you affected by CVE-2019-9345?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
