Exploitation Summary
EIP tracks 1 public exploit for CVE-2019-14040. PoCs published by tamirzb.
AI-analyzed exploit summary This repository contains a functional proof-of-concept exploit for CVE-2019-14040, a use-after-free vulnerability in Qualcomm's QSEECom driver. The exploit triggers a kernel panic on affected devices by manipulating ION memory allocations and QSEECom ioctl operations.
Description
Using memory after being freed in qsee due to wrong implementation can lead to unexpected behavior such as execution of unknown code in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8096AU, APQ8098, MDM9150, MDM9206, MDM9207C, MDM9607, MDM9640, MDM9650, MSM8905, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996AU, MSM8998, QCS605, QM215, SDA660, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM845, SDX20, SDX24, SM8150, SXR1130
Exploits (1)
This repository contains a functional proof-of-concept exploit for CVE-2019-14040, a use-after-free vulnerability in Qualcomm's QSEECom driver. The exploit triggers a kernel panic on affected devices by manipulating ION memory allocations and QSEECom ioctl operations.
References (1)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H