9.8

CVE-2021-24042

The calling logic for WhatsApp for Android prior to v2.21.23, WhatsApp Business for Android prior to v2.21.23, WhatsApp for iOS prior to v2.21.230, WhatsApp Business for iOS prior to v2.21.230, WhatsApp for KaiOS prior to v2.2143, WhatsApp Desktop prior to v2.2146 could have allowed an out-of-bounds write if a user makes a 1:1 call to a malicious actor.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
WhatsApp ≫ WhatsApp SwPlatform android HwPlatform - Version < 2.21.23
WhatsApp ≫ WhatsApp SwEdition business SwPlatform android Version < 2.21.23
WhatsApp ≫ WhatsApp SwPlatform iphone_os HwPlatform - Version < 2.21.230
WhatsApp ≫ WhatsApp SwEdition business SwPlatform iphone_os HwPlatform - Version < 2.21.230
WhatsApp ≫ WhatsApp SwPlatform kaios Version < 2.2143
WhatsApp ≫ WhatsApp SwEdition desktop SwPlatform - Version < 2.2146
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.24% 0.653
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CISA-ADP 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-122 Heap-based Buffer Overflow

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

https://www.whatsapp.com/security/advisories/2021/
Vendor Advisory
Not Applicable