CVE-2019-14514 affects Microvirt MEmu versions prior to 7.0.2, stemming from a proprietary /system/bin/systemd binary within the guest Android OS that runs with root privileges. This vulnerability allows for arbitrary command execution due to improper input validation on TCP port 21509, where shell metacharacters can be injected into a system() call. With a CVSS score of 9.8 (CRITICAL), it presents a severe risk with network-based, low-complexity attacks requiring no user interaction, leading to complete compromise of confidentiality, integrity, and availability. Currently, there is no public exploit code available (Metasploit, Nuclei, ExploitDB), and it has received minimal community discussion or media coverage, indicating a lack of widespread attention or active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 7.0.2CPE matchmatch criteria | cpe:2.3:a:microvirt:memu:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.