First published: Mon Jun 01 2020(Updated: )
In aes_cmac of aes_cmac.cc, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution in the bluetooth server with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-8.0Android ID: A-151155194
Credit: security@android.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Android | =8.0 | |
Google Android | =8.1 | |
Google Android | =9.0 | |
Google Android | =10.0 | |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-0117 is rated as a critical vulnerability due to its potential for remote code execution.
To fix CVE-2020-0117, update your Android device to the latest security patch provided by Google.
CVE-2020-0117 affects Android versions 8.0, 8.1, 9.0, and 10.0.
If exploited, CVE-2020-0117 can lead to remote code execution within the Bluetooth server without requiring user interaction.
Users with Android devices running versions 8.0 to 10.0 are vulnerable to CVE-2020-0117.