CVE-2020-0117: Integer Overflow
In aescmac of aescmac.cc, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution in the bluetooth server with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-8.0Android ID: A-151155194
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2020-0117?
CVE-2020-0117 is rated as a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2020-0117?
To fix CVE-2020-0117, update your Android device to the latest security patch provided by Google.
Which Android versions are affected by CVE-2020-0117?
CVE-2020-0117 affects Android versions 8.0, 8.1, 9.0, and 10.0.
What could happen if CVE-2020-0117 is exploited?
If exploited, CVE-2020-0117 can lead to remote code execution within the Bluetooth server without requiring user interaction.
Who is vulnerable to CVE-2020-0117?
Users with Android devices running versions 8.0 to 10.0 are vulnerable to CVE-2020-0117.