Junglewise Threat Intelligence

CVE-2020-0069: Mediatek Multiple Chipsets Insufficient Input Validation Vulnerability

CVE-2020-0069 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2021-11-03

Vendors: Google, MediaTek.

Executive brief

MediaTek Command Queue drivers contain an out-of-bounds write vulnerability due to insufficient input validation and missing SELinux restrictions in ioctl handlers. This flaw allows a local attacker to escalate privileges without user interaction. The vulnerability has been observed in the wild as part of the 'AbstractEmu' exploit chain.

Affected products

  • Google Android kernel Android kernel
  • MediaTek Command Queue driver
  • MediaTek Multiple Chipsets

Timeline

  • 2020-03-01: advisory: Android Security Bulletin - March 2020
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: disclosed: NVD Publication Date