PT-2020-10583 · Samsung · Samsung Mobile Devices

Published

2020-03-24

·

Updated

2020-03-30

·

CVE-2019-20607

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Samsung mobile devices with N(7.x) Samsung mobile devices with O(8.x) Samsung mobile devices with P(9.0)
Description An issue was discovered that allows attackers to achieve arbitrary code execution due to a heap overflow in the keymaster Trustlet, enabling them to write to TEE memory.
Recommendations For Samsung mobile devices with N(7.x), update to a version that fixes the keymaster Trustlet issue. For Samsung mobile devices with O(8.x), update to a version that fixes the keymaster Trustlet issue. For Samsung mobile devices with P(9.0), update to a version that fixes the keymaster Trustlet issue.

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-20607

Affected Products

Samsung Mobile Devices