CVE-2020-0069
In the ioctl handlers of the Mediatek Command Queue driver, there is a possible out of bounds write due to insufficient input sanitization and...
Basic Information
- CVE State
- PUBLISHED
- Reserved Date
- October 17, 2019
- Published Date
- March 10, 2020
- Last Updated
- February 07, 2025
- Vendor
- n/a
- Product
- Android
- Description
- In the ioctl handlers of the Mediatek Command Queue driver, there is a possible out of bounds write due to insufficient input sanitization and missing SELinux restrictions. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-147882143References: M-ALPS04356754
CVSS Scores
SSVC Information
- Exploitation
- active
- Technical Impact
- total
References
Known Exploited Vulnerability Information
Source | Added Date |
---|---|
CISA | 2021-11-03 00:00:00 UTC |
Potential Proof of Concepts
Warning: These PoCs have not been tested and could contain malware. Use at your own risk.
quarkslab/CVE-2020-0069_poc
Type: github • Created: 2020-03-24 13:10:39 UTC • Stars: 102