First published: Fri Jan 27 2017(Updated: )
ClipboardDataMgr in Samsung KNOX 1.0.0 and 2.3.0 does not properly check the caller, which allows local users to read KNOX clipboard data via a crafted application.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Samsung KNOX | =1.0 | |
Samsung KNOX | =2.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-3996 has been assigned a moderate severity level due to its potential to allow local users unauthorized access to clipboard data.
To fix CVE-2016-3996, ensure that you update Samsung KNOX to the latest version that addresses this vulnerability.
CVE-2016-3996 can be exploited by local users using a crafted application to gain access to KNOX clipboard data.
Users of Samsung KNOX versions 1.0.0 and 2.3.0 are affected by CVE-2016-3996.
CVE-2016-3996 is a local vulnerability, as it requires that the attacker has local access to the device.