CVE-2016-3996: Infoleak
Published Jan 27, 2017
·Updated
ClipboardDataMgr in Samsung KNOX 1.0.0 and 2.3.0 does not properly check the caller, which allows local users to read KNOX clipboard data via a crafted application.
Affected Software
2 affected components
Samsung KNOX=1.0
Samsung KNOX=2.3.0
Event History
Jan 27, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Data Sourced
via NVD·08:59 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-3996?
CVE-2016-3996 has been assigned a moderate severity level due to its potential to allow local users unauthorized access to clipboard data.
2
How do I fix CVE-2016-3996?
To fix CVE-2016-3996, ensure that you update Samsung KNOX to the latest version that addresses this vulnerability.
3
What type of attack can exploit CVE-2016-3996?
CVE-2016-3996 can be exploited by local users using a crafted application to gain access to KNOX clipboard data.
4
Who is affected by CVE-2016-3996?
Users of Samsung KNOX versions 1.0.0 and 2.3.0 are affected by CVE-2016-3996.
5
Is CVE-2016-3996 a remote or local vulnerability?
CVE-2016-3996 is a local vulnerability, as it requires that the attacker has local access to the device.