Junglewise Threat Intelligence

CVE-2020-0041: Android Kernel Out-of-Bounds Write Vulnerability

CVE-2020-0041 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2021-11-03

Vendors: Android, Google.

Executive brief

An out-of-bounds write vulnerability exists in the binder_transaction function of binder.c in the Android Kernel due to an incorrect bounds check. This flaw allows a local attacker to achieve privilege escalation without requiring user interaction.

Affected products

  • Google Android Kernel Android kernel

Timeline

  • 2020-03-10: disclosed: NVD Published Date
  • 2021-11-03: kev added: Date added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: exploited: Observed in the wild as part of the AbstractEmu exploit chain.

Related threats