packetstormsecurity.com
http://packetstormsecurity.com/files/172637/Widevine-Trustlet-5.x-6.x-7.x-PRDiagVerifyProvisioning-Buffer-Overflow.html CVE-2015-6639
HIGH
QSEE - PRDiag* Commands Privilege Escalation
Record summary
CVE-2015-6639 has a selected CVSS score of 7.8 (high); EIP currently links 1 catalogued exploit and 2 repository PoCs.
Description
The Widevine QSEE TrustZone application in Android 5.x before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to gain privileges via a crafted application that leverages QSEECOM access, aka internal bug 24446875.
Description source: CVE List
Exploitation context
Proofs of concept
3Catalogued exploits
ExploitDBQSEE - PRDiag* Commands Privilege EscalationExploitDB exploitby laginimainebNot analyzed1 file
Repository PoCs
GitHublaginimaineb/cve-2015-6639Repository PoCby laginimainebStars: 125Not analyzed15 files
GitHublaginimaineb/ExtractKeyMasterRepository PoCby laginimainebStars: 364Not analyzed25 files
References
620230530 CVE-2022-48335 - Buffer Overflow in Widevine Trustlet (PRDiagVerifyProvisioning @ 0x5f90)mailing list
http://seclists.org/fulldisclosure/2023/May/26 source.android.com
http://source.android.com/security/bulletin/2016-01-01.html 1034592vdb entry
http://www.securitytracker.com/id/1034592 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2015-6639 39757exploit
https://www.exploit-db.com/exploits/39757