First published: Fri Apr 20 2018(Updated: )
The Device Administrator code in Android before 4.4.1_r1 might allow attackers to spoof device administrators and consequently bypass MDM restrictions by leveraging failure to update the mAdminMap data structure.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Android | <=4.4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-0900 is considered a high severity vulnerability due to its potential to allow attackers to spoof device administrators.
To mitigate CVE-2014-0900, it is recommended to update Android to version 4.4.1_r1 or later.
Devices running Android versions prior to 4.4.1_r1 are affected by CVE-2014-0900.
The impact of CVE-2014-0900 includes the potential bypassing of Mobile Device Management (MDM) restrictions.
CVE-2014-0900 is less of a threat today as it affects outdated versions of Android, but users should still ensure their devices are up-to-date.