CERT-In Vulnerability Note
CIVN-2022-0370
Multiple Vulnerabilities in WhatsApp
Original Issue Date:September 27, 2022
Severity Rating: HIGH
Software Affected
- WhatsApp for Android and iOS prior to v2.22.16.12
- WhatsApp Business for Android and iOS prior to v2.22.16.12
- WhatsApp for Android prior to v2.22.16.2
- WhatsApp for iOS v2.22.15.9
Overview
Multiple Vulnerabilities have been reported in WhatsApp which could be exploited by a remote attacker to execute arbitrary code on the targeted system.
Description
1. Remote Code Execution Vulnerability
(
CVE-2022-36934
)
This vulnerability exists in WhatsApp due to integer overflow. A remote attacker could exploit this vulnerability to execute remote code in an established video call. Successful exploitation of this vulnerability could allow a remote attacker to execute arbitrary code on the targeted system.
2. Remote Code Execution Vulnerability
(
CVE-2022-27492
)
This vulnerability exists in WhatsApp due to integer underflow. A remote attacker could exploit this vulnerability by sending a specially-crafted video file. Successful exploitation of this vulnerability could allow a remote attacker to execute arbitrary code on the targeted system.
Solution
Apply appropriate updates as mentioned:
https://www.whatsapp.com/security/advisories/2022/
Vendor Information
WhatsApp
https://www.whatsapp.com/security/advisories/2022/
References
WhatsApp
https://www.whatsapp.com/security/advisories/2022/
CVE Name
CVE-2022-36934
CVE-2022-27492
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|