Use-after-free vulnerability in create_hdr of dnssd_clientstub.c in Android allows local attackers to escalate privileges via crafted input.

Use-after-free vulnerability in create_hdr of dnssd_clientstub.c in Android allows local attackers to escalate privileges via crafted input.

CVE-2019-2033 · MEDIUM Severity

AV:L/AC:L/AU:N/C:P/I:P/A:P

In create_hdr of dnssd_clientstub.c, there is a possible use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-121327565.

Learn more about our Cis Benchmark Audit For Google Android.