ASA-2019-00545 – BlueStacks: Arbitrary File Read with System admin privilege


Allele Security Alert

ASA-2019-00545

Identifier(s)

ASA-2019-00545, CVE-2019-14220, BS-2019-002

Title

Arbitrary File Read with System admin privilege

Vendor(s)

Bluestack Systems, Inc

Product(s)

BlueStacks

Affected version(s)

BlueStacks running on Windows: version 4.120 and below
BlueStacks running on MacOS: version 4.110 and below

Fixed version(s)

BlueStacks version 4.130

Proof of concept

Unknown

Description

BlueStacks employs Android running in a virtual machine (VM) to enable Android apps to run on Windows or MacOS.

Bug is in a local arbitrary file read through a system service call. The impacted method runs with System admin privilege and if given the file name as parameter returns you the content of file. A malicious app using the affected method can then read the content of any system file which it is not authorized to read.

Technical details

Unknown

Credits

Maciej Miszczyk (Seqred.pl)

Reference(s)

BlueStacks fails to restrict access permissions – BlueStacks Support
https://support.bluestacks.com/hc/en-us/articles/360033484132-BlueStacks-fails-to-restrict-access-permissions

Release Notes
https://support.bluestacks.com/hc/en-us/articles/360021469391-Release-Notes

CVE-2019-14220
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14220

CVE-2019-14220
https://nvd.nist.gov/vuln/detail/CVE-2019-14220

If there is any error in this alert or you wish a comprehensive analysis, let us know.

Last modified: September 25, 2019

We are not responsible for any data loss, device corruption or any other type of issue due to the use of any information mentioned in our security alerts.