Skip to content
COOEY

EXPOSURES › CVE-2020-0069

CVE-2020-0069

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-0069 ↗
⌖ EXPLOITED IN THE WILD SHAME 78/100 exploited-in-wildunpatchedprivilege-escalation

MediaTek chipsets suffered an out-of-bounds write vulnerability that enabled privilege escalation when chained with other known CVEs.

MediaTek chipsets contained insufficient input validation and missing SELinux restrictions in Command Queue drivers, leading to an out-of-bounds write that allowed privilege escalation. DIB organizations must ensure hardware vendors proactively patch known vulnerabilities and implement robust input validation to prevent attackers from chaining exploits for system compromise. This failure highlights the risk of relying on unpatched hardware components in critical infrastructure.

Shame score — The vulnerability was actively exploited in the wild (KEV) and chained with other known CVEs, indicating a lack of timely patching and defensive depth.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Multiple MediaTek chipsets contain an insufficient input validation vulnerability and have missing SELinux restrictions in the Command Queue drivers ioctl handlers. This causes an out-of-bounds write leading to privilege escalation. This vulnerability was observed chained with CVE-2019-2215 and CVE-2020-0041 under exploit chain "AbstractEmu."

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.60
Vulnerability in MediaTek chipsets caused privilege escalation and was chained with other CVEs, indicating significant security failure.
cooey ↗ severe-fallout -0.60
Vulnerability in MediaTek chipsets caused privilege escalation and was chained with other CVEs, indicating significant security failure.
"Multiple MediaTek chipsets contain an insufficient input validation vulnerability and have missing SELinux restrictions in the Command Queue drivers ioctl handlers. This causes an out-of-bounds write leading to privilege escalation."
www.cvefind.com ↗ severe-fallout +0.00
Neutral database listing CVEs without specific commentary on MediaTek's handling.
app.opencve.io ↗ severe-fallout +0.00
Neutral database listing CVEs without specific commentary on MediaTek's handling.
cissm.umd.edu ↗ severe-fallout +0.00
Neutral database listing CVEs without specific commentary on MediaTek's handling.
www.ransomware.live ↗ severe-fallout +0.00
Neutral database listing CVEs without specific commentary on MediaTek's handling.
cve.akaoma.com ↗ severe-fallout +0.00
Neutral database listing CVEs without specific commentary on MediaTek's handling.
guessingheadlights.com ↗ severe-fallout +0.00
Neutral article unrelated to MediaTek CVE-2020-0069.
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.