« Volver al listado

CVE-2025-5099

Estado: AnalizadaCrítica (9.8)—

An Out of Bounds Write occurs when the native library attempts PDF rendering, which can be exploited to achieve memory corruption and potentially arbitrary code execution.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vector CVSS AV:N/AC:L/PR:N/UI:N indica acceso remoto sin privilegios ni interacción; Out of Bounds Write en librería nativa permite corrupción de memoria y ejecución arbitraria de código (RCE). PrinterShare es servicio remoto expuesto.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-5099",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-5099",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "poc"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-05-23T15:40:23.497578Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "bbf0bd87-ece2-41be-b873-96928ee8fab9",
      "affectedData": [
        {
          "vendor": "Mobile Dynamix",
          "product": "PrinterShare Mobile Print",
          "versions": [
            {
              "status": "affected",
              "version": "12.15.01"
            }
          ],
          "platforms": [
            "Android"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2025-05-23T02:15:22.383",
  "references": [
    {
      "url": "https://korelogic.com/Resources/Advisories/KL-001-2025-004.txt",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "bbf0bd87-ece2-41be-b873-96928ee8fab9"
    },
    {
      "url": "https://korelogic.com/Resources/Advisories/KL-001-2025-004.txt",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "bbf0bd87-ece2-41be-b873-96928ee8fab9",
      "description": [
        {
          "lang": "en",
          "value": "CWE-119"
        },
        {
          "lang": "en",
          "value": "CWE-787"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An Out of Bounds Write occurs when the native library attempts PDF rendering, which can be exploited to achieve memory corruption and potentially arbitrary code execution."
    },
    {
      "lang": "es",
      "value": "Una escritura fuera de límites ocurre cuando la librería nativa intenta renderizar PDF, lo que puede aprovecharse para lograr corrupción de memoria y potencialmente ejecución de código arbitrario."
    }
  ],
  "lastModified": "2026-06-17T09:47:11.690",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:dynamixsoftware:printershare:*:*:*:*:*:android:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E3EE578E-04AA-45B3-805A-DAE573DA7763",
              "versionEndIncluding": "12.15.01"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "bbf0bd87-ece2-41be-b873-96928ee8fab9"
}