5.5
CVSSv3

CVE-2019-11419

Published: 14/05/2019 Updated: 01/03/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

vcodec2_hls_filter in libvoipCodec_v7a.so in the WeChat application up to and including 7.0.3 for Android allows malicious users to cause a denial of service (application crash) by replacing an emoji file (under the /sdcard/tencent/MicroMsg directory) with a crafted .wxgf file. The content of the replacement must be derived from the phone's IMEI. The crash occurs upon receiving a message that contains the replaced emoji.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

tencent wechat

Exploits

# Exploit Title: DoS Wechat with an emoji # Date: 16-May-2019 # Exploit Author: Hong Nhat Pham # Vendor Homepage: wwwtencentcom/en-us/indexhtml # Software Link: playgooglecom/store/apps/details?id=comtencentmm # Version: 704 # Tested on: Android 90 # CVE : CVE-2019-11419 Description: vcodec2_hls_filter in libvoipCodec_v7a ...