cbcvebase.
CVE-2020-0227
published 2020-07-17

CVE-2020-0227: In onCommand of CompanionDeviceManagerService.java, there is a possible permissions bypass due to a missing permission check. This could lead to local…

PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.27%
18.4th percentile
In onCommand of CompanionDeviceManagerService.java, there is a possible permissions bypass due to a missing permission check. This could lead to local escalation of privilege allowing background data usage or launching from the background, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-129476618

Affected

17 ranges
VendorProductVersion rangeFixed in
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
platformcts>= 10:0 < 10:2020-07-0110:2020-07-01
platformcts>= 8.0:0 < 8.0:2020-07-018.0:2020-07-01
platformcts>= 8.1:0 < 8.1:2020-07-018.1:2020-07-01
platformcts>= 9:0 < 9:2020-07-019:2020-07-01
platformframeworks_base>= 10:0 < 10:2020-07-0110:2020-07-01
platformframeworks_base>= 8.0:0 < 8.0:2020-07-018.0:2020-07-01
platformframeworks_base>= 8.1:0 < 8.1:2020-07-018.1:2020-07-01
platformframeworks_base>= 9:0 < 9:2020-07-019:2020-07-01

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vendor_oracle7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.