CVE-2019-3568
critical · 9.8Actively exploitedOn the CISA Known Exploited Vulnerabilities catalog
Apply updates per vendor instructions.
Added 2022-04-19Remediation due 2022-05-10
A buffer overflow vulnerability in WhatsApp VOIP stack allowed remote code execution via specially crafted series of RTCP packets sent to a target phone number. The issue affects WhatsApp for Android prior to v2.19.134, WhatsApp Business for Android prior to v2.19.44, WhatsApp for iOS prior to v2.19.51, WhatsApp Business for iOS prior to v2.19.51, WhatsApp for Windows Phone prior to v2.18.348, and WhatsApp for Tizen prior to v2.18.15.
9.8
CVSS
30.1%
EPSS (exploit prob.)
98th
EPSS percentile
2019-05-14
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-122CWE-787
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| < 2.18.15 | ||
| < 2.18.348 | ||
| < 2.19.51 | ||
| < 2.19.134 | ||
| whatsapp_business | < 2.19.44 | |
| whatsapp_business | < 2.19.51 |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2019-3568