Record summary

CVE-2015-6639 has a selected CVSS score of 7.8 (high); EIP currently links 1 catalogued exploit and 2 repository PoCs.

Description

The Widevine QSEE TrustZone application in Android 5.x before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to gain privileges via a crafted application that leverages QSEECOM access, aka internal bug 24446875.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Repository PoCs
2

Proofs of concept

3

Catalogued exploits

ExploitDBQSEE - PRDiag* Commands Privilege EscalationExploitDB exploitby laginimainebNot analyzed1 file
ExploitDB

PoC details

Repository PoCs

GitHublaginimaineb/cve-2015-6639Repository PoCby laginimainebStars: 125Not analyzed15 files

67.3 KiB

GitHub

PoC details
GitHublaginimaineb/ExtractKeyMasterRepository PoCby laginimainebStars: 364Not analyzed25 files

95.5 KiB · linked to 2 vulnerabilities

GitHub

PoC details

References

6