CVE-2025-34449
🔴 Łataj teraz
Przepełnienie bufora w scrcpy umożliwia zdalne wykonanie kodu lub awarię systemu.
CVSS
9.1
EPSS
0.4%
Exploit
poc
Vendor
genymotion
Opis źródłowy (NVD)
Genymobile/scrcpy versions up to and including 3.3.3, prior to commit 3e40b24, contain a buffer overflow vulnerability in the sc_device_msg_deserialize() function. A compromised device can send crafted messages that cause out-of-bounds reads, which may result in memory corruption or a denial-of-service condition. This vulnerability may allow further exploitation on the host system.
buffer-overflow exploit
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 9.1 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.4% |
| Opublikowano (NVD) | 2025-12-18 22:15:56 UTC |
| Ostatnia modyfikacja (NVD) | 2026-09-30 23:10:00 UTC |
Referencje
- https://github.com/Genymobile/scrcpy/commit/3e40b24 ([email protected]) [Patch]
- https://github.com/Genymobile/scrcpy/issues/6415 ([email protected]) [Exploit, Issue Tracking, Patch]
- https://github.com/marlinkcyber/advisories/blob/main/advisories/MCSAID-2025-003-scrcpy-global-buffer-overflow.md ([email protected]) [Exploit, Third Party Advisory]
- https://www.vulncheck.com/advisories/genymobile-scrcpy-global-buffer-overflow ([email protected]) [Third Party Advisory]