Skip to content
COOEY

EXPOSURES › CVE-2020-0041

CVE-2020-0041

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-0041 ↗
⌖ EXPLOITED IN THE WILD SHAME 78/100 exploited-in-wildunpatchedprivilege-escalation

An out-of-bounds write vulnerability in the Android kernel allowed local privilege escalation when chained with other known CVEs.

The Android kernel's incorrect bounds check in binder.c enabled local privilege escalation, which was actively exploited in the wild as part of the AbstractEmu exploit chain. DIB organizations must ensure their mobile devices are patched against this and related CVEs to prevent attackers from escalating privileges and compromising device integrity. This failure highlights the risk of relying on unpatched, known vulnerabilities that are actively exploited.

Shame score — A known, actively exploited vulnerability in a widely deployed OS component that was chained with other CVEs to achieve privilege escalation, demonstrating severe negligence in patch management and supply chain security.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Android Kernel binder_transaction of binder.c contains an out-of-bounds write vulnerability due to an incorrect bounds check that could allow for local privilege escalation. This vulnerability was observed chained with CVE-2019-2215 and CVE-2020-0069 under exploit chain "AbstractEmu."

SENTIMENT · TRUSTED SOURCES
synthesis neutral +0.00
No sentiment expressed; purely factual NVD entry.
cooey ↗ neutral +0.00
No sentiment expressed; purely factual NVD entry.
"Android Kernel binder_transaction of binder.c contains an out-of-bounds write vulnerability due to an incorrect bounds check that could allow for local privilege escalation."
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.