CVE-2020-0069
published 2020-03-10CVE-2020-0069: In the ioctl handlers of the Mediatek Command Queue driver, there is a possible out of bounds write due to insufficient input sanitization and missing SELinux…
PriorityP180high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2022-05-03
Exploited in the wild
EPSS
1.30%
67.2th percentile
In the ioctl handlers of the Mediatek Command Queue driver, there is a possible out of bounds write due to insufficient input sanitization and missing SELinux restrictions. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-147882143References: M-ALPS04356754
Affected
42 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| huawei | berkeley-l09_firmware | < 10.0.0.177\(c10e3r1p4\) | 10.0.0.177\(c10e3r1p4\) |
| huawei | columbia-al10b_firmware | < 10.0.0.178\(c00e178r1p4\) | 10.0.0.178\(c00e178r1p4\) |
| huawei | columbia-l29d_firmware | < 10.0.0.177\(c10e4r1p4\) | 10.0.0.177\(c10e4r1p4\) |
| huawei | columbia-l29d_firmware | < 10.0.0.177\(c432e3r1p4\) | 10.0.0.177\(c432e3r1p4\) |
| huawei | columbia-tl00b_firmware | < 10.0.0.178\(c01e178r1p4\) | 10.0.0.178\(c01e178r1p4\) |
| huawei | columbia-tl00d_firmware | < 10.0.0.178\(c01e178r1p4\) | 10.0.0.178\(c01e178r1p4\) |
| huawei | cornell-al00a_firmware | < 9.1.0.340\(c00e333r1p1t8\) | 9.1.0.340\(c00e333r1p1t8\) |
| huawei | cornell-tl10b_firmware | < 9.1.0.340\(c01e333r1p1t8\) | 9.1.0.340\(c01e333r1p1t8\) |
| huawei | dura-al00a_firmware | < 1.0.0.190\(c00\) | 1.0.0.190\(c00\) |
| huawei | honor_20_pro_firmware | < 10.0.0.194\(c636e3r3p1\) | 10.0.0.194\(c636e3r3p1\) |
| huawei | honor_20_pro_firmware | < 10.0.0.202\(c10e3r3p2\) | 10.0.0.202\(c10e3r3p2\) |
| huawei | honor_8a_firmware | < 9.1.0.291\(c185e3r4p1\) | 9.1.0.291\(c185e3r4p1\) |
| huawei | honor_8a_firmware | < 9.1.0.291\(c432e5r2p1\) | 9.1.0.291\(c432e5r2p1\) |
| huawei | honor_8a_firmware | < 9.1.0.291\(c636e4r4p1\) | 9.1.0.291\(c636e4r4p1\) |
| huawei | honor_8a_firmware | < 9.1.0.297\(c605e4r4p2\) | 9.1.0.297\(c605e4r4p2\) |
| huawei | honor_view_20_firmware | < 10.0.0.198\(c432e10r3p4\) | 10.0.0.198\(c432e10r3p4\) |
| huawei | honor_view_20_firmware | < 10.0.0.200\(c185e3r3p3\) | 10.0.0.200\(c185e3r3p3\) |
| huawei | honor_view_20_firmware | < 10.0.0.201\(c10e5r4p3\) | 10.0.0.201\(c10e5r4p3\) |
| huawei | jakarta-al00a_firmware | < 9.1.0.251\(c00e106r2p2\) | 9.1.0.251\(c00e106r2p2\) |
| huawei | katyusha-al00a_firmware | < 9.1.0.146\(c00e131r2p2\) | 9.1.0.146\(c00e131r2p2\) |
| huawei | katyusha-al10a_firmware | < 9.1.0.160\(c00e150r1p7\) | 9.1.0.160\(c00e150r1p7\) |
| huawei | madrid-al00a_firmware | < 9.1.0.261\(c00e120r4p1\) | 9.1.0.261\(c00e120r4p1\) |
| huawei | nova_3_firmware | < 9.1.0.338\(c00e333r1p1t8\) | 9.1.0.338\(c00e333r1p1t8\) |
| huawei | nova_4_firmware | < 10.0.0.160\(c01e32r2p4\) | 10.0.0.160\(c01e32r2p4\) |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2020-0069 is exploited in the wild as part of the 'AbstractEmu' exploit chain, chained with CVE-2019-2215 and CVE-2020-0041 for privilege escalation ↗
- →The vulnerability is triggered via ioctl handlers of the MediaTek Command Queue driver; monitor for unexpected ioctl calls to MediaTek Command Queue device nodes from unprivileged processes ↗
- →Exploitation requires no additional privileges and no user interaction; any local process can attempt exploitation — monitor for privilege escalation from low-privileged or untrusted domains ↗
- ·The vulnerability affects multiple MediaTek chipsets; the missing SELinux restrictions are a prerequisite — devices with properly enforced SELinux policy confining access to the Command Queue driver are not exploitable via this path ↗
- ·Manufacturer-customized SELinux policy rules (unregulated rules) are the root enabler on affected devices; the base AOSP policy strictly confines access to sensitive device nodes and would block this exploit ↗
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
ghsa5.3MEDIUM
vulncheck7.8HIGH
cisa7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xx48-fp29-wh9j: In the ioctl handlers of the Mediatek Command Queue driver, there is a possible out of bounds write due to insufficient input sanitization and missing
ghsa_unreviewed·2022-05-24
CVE-2020-0069 [HIGH] CWE-787 GHSA-xx48-fp29-wh9j: In the ioctl handlers of the Mediatek Command Queue driver, there is a possible out of bounds write due to insufficient input sanitization and missing
In the ioctl handlers of the Mediatek Command Queue driver, there is a possible out of bounds write due to insufficient input sanitization and missing SELinux restrictions. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-147882143References: M-ALPS04356754
GHSA
Argument injection in lettre
ghsa·2021-08-25·CVSS 5.3
CVE-2020-28247 [MEDIUM] CWE-77 Argument injection in lettre
Argument injection in lettre
### Impact
Affected versions of lettre allowed argument injection to the sendmail command. It was possible, using forged to addresses, to pass arbitrary arguments to the sendmail executable.
Depending on the implementation (original sendmail, postfix, exim, etc.) it could be possible in some cases to write email data into abritrary files (using sendmail's logging features).
*NOTE*: This vulnerability only affects the sendmail transport. Others, including smtp, are not affected.
### Fix
The flaw is corrected by modifying the executed command to stop parsing arguments before passing the destination addresses.
### References
* [RUSTSEC-2020-0069](https://rustsec.org/advisories/RUSTSEC-2020-0069.html)
* [CVE-2020-28247](https://nvd.nist.gov/vuln/detail/CVE-
VulnCheck
Mediatek Multiple Chipsets Insufficient Input Validation Vulnerability
vulncheck·2020·CVSS 7.8
CVE-2020-0069 [HIGH] CWE-787 Mediatek Multiple Chipsets Insufficient Input Validation Vulnerability
Mediatek Multiple Chipsets Insufficient Input Validation Vulnerability
Multiple MediaTek chipsets contain an insufficient input validation vulnerability and have missing SELinux restrictions in the Command Queue drivers ioctl handlers. This causes an out-of-bounds write leading to privilege escalation. This vulnerability was observed chained with CVE-2019-2215 and CVE-2020-0041 under exploit chain "AbstractEmu."
Affected: MediaTek Multiple Chipsets
Required Action: Apply updates per vendor instructions.
Exploitation References: https://www.lookout.com/threat-intelligence/article/lookout-discovers-global-rooting-malware-campaign; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
Exploit PoC: https://vulncheck.com/xdb/9a931c619e3c; https://vulncheck.com
VulnCheck
Android Kernel Out-of-Bounds Write Vulnerability
vulncheck·2020·CVSS 7.8
CVE-2020-0041 [HIGH] CWE-20 Android Kernel Out-of-Bounds Write Vulnerability
Android Kernel Out-of-Bounds Write Vulnerability
Android Kernel binder_transaction of binder.c contains an out-of-bounds write vulnerability due to an incorrect bounds check that could allow for local privilege escalation. This vulnerability was observed chained with CVE-2019-2215 and CVE-2020-0069 under exploit chain "AbstractEmu."
Affected: Android Android
Required Action: Apply updates per vendor instructions.
Exploitation References: https://www.lookout.com/threat-intelligence/article/lookout-discovers-global-rooting-malware-campaign; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
Exploit PoC: https://vulncheck.com/xdb/b8a8ac784158; https://vulncheck.com/xdb/95ece15b5070; https://vulncheck.com/xdb/c2368cc50b93
Remediation Due: 2022-05-03
VulnCheck
Android Kernel Use-After-Free Vulnerability
vulncheck·2019·CVSS 7.8
CVE-2019-2215 [HIGH] CWE-416 Android Kernel Use-After-Free Vulnerability
Android Kernel Use-After-Free Vulnerability
Android Kernel contains a use-after-free vulnerability in binder.c that allows for privilege escalation from an application to the Linux Kernel. This vulnerability was observed chained with CVE-2020-0041 and CVE-2020-0069 under exploit chain "AbstractEmu."
Affected: Android Android
Required Action: Apply updates per vendor instructions.
Exploitation References: https://bugs.chromium.org/p/project-zero/issues/detail?id=1942#c7; https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit; https://www.trendmicro.com/en_us/research/20/a/first-active-attack-exploiting-cve-2019-2215-found-on-google-play-linked-to-sidewinder-apt-group.html; https://www.trendmicro.com/en_us/research/20/l/sidewinder-leverages-south-asian-t
CISA
Mediatek Multiple Chipsets Insufficient Input Validation Vulnerability
cisa·2021-11-03·CVSS 7.8
CVE-2020-0069 [HIGH] CWE-787 Mediatek Multiple Chipsets Insufficient Input Validation Vulnerability
Vulnerability: Mediatek Multiple Chipsets Insufficient Input Validation Vulnerability
Affected: MediaTek Multiple Chipsets
Multiple MediaTek chipsets contain an insufficient input validation vulnerability and have missing SELinux restrictions in the Command Queue drivers ioctl handlers. This causes an out-of-bounds write leading to privilege escalation. This vulnerability was observed chained with CVE-2019-2215 and CVE-2020-0041 under exploit chain "AbstractEmu."
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2020-0069
Remediation Due Date: 2022-05-03
CISA
Android Kernel Out-of-Bounds Write Vulnerability
cisa·2021-11-03·CVSS 7.8
CVE-2020-0041 [HIGH] CWE-20 Android Kernel Out-of-Bounds Write Vulnerability
Vulnerability: Android Kernel Out-of-Bounds Write Vulnerability
Affected: Android Android Kernel
Android Kernel binder_transaction of binder.c contains an out-of-bounds write vulnerability due to an incorrect bounds check that could allow for local privilege escalation. This vulnerability was observed chained with CVE-2019-2215 and CVE-2020-0069 under exploit chain "AbstractEmu."
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2020-0041
Remediation Due Date: 2022-05-03
CISA
Android Kernel Use-After-Free Vulnerability
cisa·2021-11-03·CVSS 7.8
CVE-2019-2215 [HIGH] CWE-416 Android Kernel Use-After-Free Vulnerability
Vulnerability: Android Kernel Use-After-Free Vulnerability
Affected: Android Android Kernel
Android Kernel contains a use-after-free vulnerability in binder.c that allows for privilege escalation from an application to the Linux Kernel. This vulnerability was observed chained with CVE-2020-0041 and CVE-2020-0069 under exploit chain "AbstractEmu."
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2019-2215
Remediation Due Date: 2022-05-03
Android
CVE-2020-0069: System
vendor_android·2020-03-01·CVSS 7.8
CVE-2020-0069 [HIGH] CVE-2020-0069: System
Android Security Bulletin 2020-03-01
CVE: CVE-2020-0069
Severity: HIGH
Type: EoP
Component: System
References: A-147882143*
M-ALPS04356754
No detection rules found.
No public exploits indexed.
http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200527-01-mtk-enhttps://source.android.com/security/bulletin/2020-03-01http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200527-01-mtk-enhttps://source.android.com/security/bulletin/2020-03-01https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-0069
2020-03-10
Published
2021-11-03
Added to CISA KEV
Exploited in the wild