CVE-2018-10751
MEDIUMSamsung Mobile - Memory Corruption via OMACP WbXml String Extension Processing
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-10751. PoCs published by Google Security Research.
AI-analyzed exploit summary The exploit leverages an integer overflow in Samsung's OMACP WAP push SMS handling, causing memory corruption and a crash (DoS) on Samsung S7 Edge devices. The malformed WbXML payload triggers the vulnerability pre-authentication during credential extraction.
Description
A malformed OMACP WAP push message can cause memory corruption on a Samsung S7 Edge device when processing the String Extension portion of the WbXml payload. This is due to an integer overflow in memory allocation for this string. The Samsung ID is SVE-2018-11463.
Exploits (1)
The exploit leverages an integer overflow in Samsung's OMACP WAP push SMS handling, causing memory corruption and a crash (DoS) on Samsung S7 Edge devices. The malformed WbXML payload triggers the vulnerability pre-authentication during credential extraction.
References (3)
Scores
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H