CVE-2020-0041
In binder_transaction of binder.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of...
Basic Information
- CVE State
- PUBLISHED
- Reserved Date
- October 17, 2019
- Published Date
- March 10, 2020
- Last Updated
- February 07, 2025
- Vendor
- Product
- Android
- Description
- In binder_transaction of binder.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-145988638References: Upstream kernel
- Tags
- Exploitation
- active
- Technical Impact
- total
CVSS Scores
CVSS v3.1
Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C
SSVC Information
Known Exploited Vulnerability Information
Source | Added Date |
---|---|
CISA | 2021-11-03 00:00:00 UTC |
Potential Proof of Concepts
Warning: These PoCs have not been tested and could contain malware. Use at your own risk.
vaginessa/CVE-2020-0041-Pixel-3a
Type: github • Created: 2023-08-14 01:46:47 UTC • Stars: 3
koharin/CVE-2020-0041
Type: github • Created: 2021-09-10 08:01:54 UTC • Stars: 0
j4nn/CVE-2020-0041
Type: github • Created: 2020-08-10 21:34:16 UTC • Stars: 53
bluefrostsecurity/CVE-2020-0041
Type: github • Created: 2020-03-31 17:53:57 UTC • Stars: 234
Timeline
-
CVE ID Reserved
-
CVE Published to Public
-
Proof of Concept Exploit Available
-
Added to KEVIntel