cbcvebase.
CVE-2020-0069
published 2020-03-10

CVE-2020-0069: In the ioctl handlers of the Mediatek Command Queue driver, there is a possible out of bounds write due to insufficient input sanitization and missing SELinux…

PriorityP180high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2022-05-03
Exploited in the wild
EPSS
1.30%
67.2th percentile
In the ioctl handlers of the Mediatek Command Queue driver, there is a possible out of bounds write due to insufficient input sanitization and missing SELinux restrictions. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-147882143References: M-ALPS04356754

Affected

42 ranges· showing 25
VendorProductVersion rangeFixed in
googleandroid
huaweiberkeley-l09_firmware< 10.0.0.177\(c10e3r1p4\)10.0.0.177\(c10e3r1p4\)
huaweicolumbia-al10b_firmware< 10.0.0.178\(c00e178r1p4\)10.0.0.178\(c00e178r1p4\)
huaweicolumbia-l29d_firmware< 10.0.0.177\(c10e4r1p4\)10.0.0.177\(c10e4r1p4\)
huaweicolumbia-l29d_firmware< 10.0.0.177\(c432e3r1p4\)10.0.0.177\(c432e3r1p4\)
huaweicolumbia-tl00b_firmware< 10.0.0.178\(c01e178r1p4\)10.0.0.178\(c01e178r1p4\)
huaweicolumbia-tl00d_firmware< 10.0.0.178\(c01e178r1p4\)10.0.0.178\(c01e178r1p4\)
huaweicornell-al00a_firmware< 9.1.0.340\(c00e333r1p1t8\)9.1.0.340\(c00e333r1p1t8\)
huaweicornell-tl10b_firmware< 9.1.0.340\(c01e333r1p1t8\)9.1.0.340\(c01e333r1p1t8\)
huaweidura-al00a_firmware< 1.0.0.190\(c00\)1.0.0.190\(c00\)
huaweihonor_20_pro_firmware< 10.0.0.194\(c636e3r3p1\)10.0.0.194\(c636e3r3p1\)
huaweihonor_20_pro_firmware< 10.0.0.202\(c10e3r3p2\)10.0.0.202\(c10e3r3p2\)
huaweihonor_8a_firmware< 9.1.0.291\(c185e3r4p1\)9.1.0.291\(c185e3r4p1\)
huaweihonor_8a_firmware< 9.1.0.291\(c432e5r2p1\)9.1.0.291\(c432e5r2p1\)
huaweihonor_8a_firmware< 9.1.0.291\(c636e4r4p1\)9.1.0.291\(c636e4r4p1\)
huaweihonor_8a_firmware< 9.1.0.297\(c605e4r4p2\)9.1.0.297\(c605e4r4p2\)
huaweihonor_view_20_firmware< 10.0.0.198\(c432e10r3p4\)10.0.0.198\(c432e10r3p4\)
huaweihonor_view_20_firmware< 10.0.0.200\(c185e3r3p3\)10.0.0.200\(c185e3r3p3\)
huaweihonor_view_20_firmware< 10.0.0.201\(c10e5r4p3\)10.0.0.201\(c10e5r4p3\)
huaweijakarta-al00a_firmware< 9.1.0.251\(c00e106r2p2\)9.1.0.251\(c00e106r2p2\)
huaweikatyusha-al00a_firmware< 9.1.0.146\(c00e131r2p2\)9.1.0.146\(c00e131r2p2\)
huaweikatyusha-al10a_firmware< 9.1.0.160\(c00e150r1p7\)9.1.0.160\(c00e150r1p7\)
huaweimadrid-al00a_firmware< 9.1.0.261\(c00e120r4p1\)9.1.0.261\(c00e120r4p1\)
huaweinova_3_firmware< 9.1.0.338\(c00e333r1p1t8\)9.1.0.338\(c00e333r1p1t8\)
huaweinova_4_firmware< 10.0.0.160\(c01e32r2p4\)10.0.0.160\(c01e32r2p4\)

Detection & IOCsextracted from sources · hover to see the quote

  • CVE-2020-0069 is exploited in the wild as part of the 'AbstractEmu' exploit chain, chained with CVE-2019-2215 and CVE-2020-0041 for privilege escalation
  • The vulnerability is triggered via ioctl handlers of the MediaTek Command Queue driver; monitor for unexpected ioctl calls to MediaTek Command Queue device nodes from unprivileged processes
  • Exploitation requires no additional privileges and no user interaction; any local process can attempt exploitation — monitor for privilege escalation from low-privileged or untrusted domains
  • ·The vulnerability affects multiple MediaTek chipsets; the missing SELinux restrictions are a prerequisite — devices with properly enforced SELinux policy confining access to the Command Queue driver are not exploitable via this path
  • ·Manufacturer-customized SELinux policy rules (unregulated rules) are the root enabler on affected devices; the base AOSP policy strictly confines access to sensitive device nodes and would block this exploit

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
ghsa5.3MEDIUM
vulncheck7.8HIGH
cisa7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.