VDB

CVE-2019-3568

CVE-2019-3568 PUBLISHED KEV CVSS 9.800000190734863 CRITICAL

A buffer overflow vulnerability in WhatsApp VOIP stack allowed remote code execution via specially crafted series of SRTCP packets sent to a target phone number. The issue affects WhatsApp for Android prior to v2.19.134, WhatsApp Business for Android prior to v2.19.44, WhatsApp for iOS prior to v2.19.51, WhatsApp Business for iOS prior to v2.19.51, WhatsApp for Windows Phone prior to v2.18.348, and WhatsApp for Tizen prior to v2.18.15.

EPSS 30.08% · 98.1th percentile

Risk Scores

CVSS 3.0
9.800000190734863
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
30.08%
98.1th percentile

Affected Products

VendorProductVersions
FacebookWhatsApp Business for iOS*, 2.19.51
FacebookWhatsApp for Windows Phone2.18.348, unspecified
FacebookWhatsApp for iOS*, 2.19.51
whatsappwhatsapp0, 0, 0
FacebookWhatsApp for Tizenunspecified, 2.18.15
FacebookWhatsApp Business for Android2.19.44, *
FacebookWhatsApp for Android2.19.134, unspecified
whatsappwhatsapp_business0, 0

Timeline

  • May 13, 2019 VulnCheck KEV Exploitation
  • May 13, 2019 PoC Published
  • May 14, 2019 CVE Published
  • Apr 14, 2021 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Apr 18, 2022 PoC Published
  • Apr 19, 2022 CISA KEV Added
  • Apr 19, 2022 VulnCheck KEV Exploitation
  • May 8, 2023 EPSS Score
  • Jun 14, 2023 PoC Published
  • Feb 6, 2024 VulnCheck KEV Exploitation
  • Jul 3, 2024 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›