CVE-2020-0199
published 2020-06-11CVE-2020-0199: In TimeCheck::TimeCheckThread::threadLoop of TimeCheck.cpp, there is a possible use-after-free due to a race condition. This could lead to local information…
PriorityP415medium4.1CVSS 3.1
AVLACHPRHUINSUCHINAN
EPSS
0.10%
1.1th percentile
In TimeCheck::TimeCheckThread::threadLoop of TimeCheck.cpp, there is a possible use-after-free due to a race condition. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-142142406
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — |
CVSS provenance
nvdv3.14.1MEDIUMCVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N
nvdv2.01.9LOWAV:L/AC:M/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Suricata
ET MALWARE HTTP Andromeda File Request
suricata·2017-07-21
CVE-2017-0199 ET MALWARE HTTP Andromeda File Request
ET MALWARE HTTP Andromeda File Request
Rule: alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET MALWARE HTTP Andromeda File Request"; flow:established,to_server; http.uri; content:"myguy"; fast_pattern; pcre:"/myguy\.(?:xls(?:\.hta)?|exe)$/"; reference:url,gist.github.com/vulnersCom/65fe44d27d29d7a5de4c176baba45759; reference:cve,2017-0199; classtype:trojan-activity; sid:2024490; rev:5; metadata:created_at 2017_07_21, cve CVE_2017_0199, confidence High, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2020_10_09;)
Suricata
ET WEB_CLIENT Office Discovery HTA file Likely CVE-2017-0199 Request M2
suricata·2017-04-19·CVSS 7.8
CVE-2017-0199 [HIGH] ET WEB_CLIENT Office Discovery HTA file Likely CVE-2017-0199 Request M2
ET WEB_CLIENT Office Discovery HTA file Likely CVE-2017-0199 Request M2
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET WEB_CLIENT Office Discovery HTA file Likely CVE-2017-0199 Request M2"; flow:established,to_client; flowbits:isset,Office.UA; http.content_type; content:"application/hta"; nocase; endswith; fast_pattern; reference:cve,cve-2017-0199; classtype:trojan-activity; sid:2024226; rev:3; metadata:affected_product Windows_XP_Vista_7_8_10_Server_32_64_Bit, affected_product Web_Browser_Plugins, attack_target Client_Endpoint, created_at 2017_04_19, deployment Perimeter, malware_family Exploit_Kit_RIG, performance_impact Low, confidence Medium, signature_severity Major, tag Exploit_kit_RIG, tag CISA_KEV, updated_at 2020_10_09;)
No public exploits indexed.
No writeups or analysis indexed.
2020-06-11
Published