VDB
CVE-2019-3568
CVE-2019-3568
PUBLISHED
KEV
CVSS 9.800000190734863 CRITICAL
A buffer overflow vulnerability in WhatsApp VOIP stack allowed remote code execution via specially crafted series of SRTCP packets sent to a target phone number. The issue affects WhatsApp for Android prior to v2.19.134, WhatsApp Business for Android prior to v2.19.44, WhatsApp for iOS prior to v2.19.51, WhatsApp Business for iOS prior to v2.19.51, WhatsApp for Windows Phone prior to v2.18.348, and WhatsApp for Tizen prior to v2.18.15.
EPSS 30.08% · 98.1th percentile
Risk Scores
CVSS 3.0
9.800000190734863
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
30.08%
98.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| WhatsApp Business for iOS | *, 2.19.51 | |
| WhatsApp for Windows Phone | 2.18.348, unspecified | |
| WhatsApp for iOS | *, 2.19.51 | |
| 0, 0, 0 | ||
| WhatsApp for Tizen | unspecified, 2.18.15 | |
| WhatsApp Business for Android | 2.19.44, * | |
| WhatsApp for Android | 2.19.134, unspecified | |
| whatsapp_business | 0, 0 |
Timeline
- May 13, 2019 VulnCheck KEV Exploitation
- May 13, 2019 PoC Published
- May 14, 2019 CVE Published
- Apr 14, 2021 EPSS Score
- Feb 4, 2022 EPSS Score
- Apr 18, 2022 PoC Published
- Apr 19, 2022 CISA KEV Added
- Apr 19, 2022 VulnCheck KEV Exploitation
- May 8, 2023 EPSS Score
- Jun 14, 2023 PoC Published
- Feb 6, 2024 VulnCheck KEV Exploitation
- Jul 3, 2024 EPSS Score