PT-2020-11755 · Google · Android Kernel
Published
2020-09-17
·
Updated
2020-09-23
·
CVE-2020-0403
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Android kernel
Description
The issue is related to an exposed test feature in the FPC TrustZone fingerprint App, which could lead to a local escalation of privilege in the TEE. System execution privileges are required for exploitation, and user interaction is not needed.
Recommendations
For Android kernel, consider restricting access to the test feature in the FPC TrustZone fingerprint App to minimize the risk of exploitation. As a temporary workaround, disabling the exposed test feature until a patch is available may help mitigate the issue.
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Android Kernel