CVE-2020-0038: High severity Google Android vulnerability
Published Mar 2, 2020
·Updated
In rwi93smupdatendef of rwi93.cc, there is a possible read of uninitialized data due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-143109193
Affected Software
5 affected components
Google Android=8.0
Google Android=8.1
Google Android=9.0
Google Android=10.0
Google Android
Event History
Mar 2, 2020
CVE Published
via Android·12:00 AM
Data Sourced
via Android·12:00 AM
SeverityWeaknessAffected Software
Mar 10, 2020
CVE Published
via MITRE·07:56 PM
Data Sourced
via MITRE·07:56 PM
DescriptionWeakness
Frequently Asked Questions
1
Which Android releases are identified as affected?
Android 8.0, 8.1, 9, and 10 are listed as affected.
2
What level of attacker access or interaction is required?
The vulnerability is remotely exploitable with no privileges and requires no user interaction.
3
What is the potential impact?
Successful exploitation could disclose uninitialized data. The CVSS vector indicates high confidentiality impact, with no integrity or availability impact.