CVE-2020-0039: High severity Google Android vulnerability
Published Mar 2, 2020
·Updated
In rwi93smupdatendef of rwi93.cc, there is a possible read of uninitialized data due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-143155861
Affected Software
5 affected components
Google Android=8.0
Google Android=8.1
Google Android=9.0
Google Android=10.0
Google Android
Event History
Mar 2, 2020
CVE Published
via Android·12:00 AM
Data Sourced
via Android·12:00 AM
SeverityWeaknessAffected Software
Mar 10, 2020
CVE Published
via MITRE·07:56 PM
Data Sourced
via MITRE·07:56 PM
DescriptionWeakness
Frequently Asked Questions
1
Which Android releases are identified as affected?
Android 8.0, 8.1, 9, and 10 are listed as affected.
2
What access does an attacker need to exploit this issue?
The issue is remotely exploitable without privileges or user interaction. The CVSS vector identifies network attack access, low attack complexity, and no required privileges.
3
What is the expected impact if exploitation succeeds?
Successful exploitation could disclose uninitialized data. The listed CVSS impact is high confidentiality impact, with no integrity or availability impact.