PoC Index

CVE-2019-2215

KEVHIGH 7.8EPSS 72.1%

A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit this vulnerability, however exploitation does require either the installation of a malicious local application or a separate vulnerability in a network facing application.Product: AndroidAndroid ID: A-141720095

CVSS v3.1
7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v3.1
7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
4.6 MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
EPSS
72.10% chance of exploitation in the next 30 days, 99th percentile
CISA KEV
added 2021-11-03
Published
2019-10-11
Updated
2025-10-21

Proof-of-concept exploits (37)

Metasploit modules (1)

ExploitDB entries (2)

References

Related