PT-2020-11783 · Google · Android

Published

2020-12-01

·

Updated

2022-07-12

·

CVE-2020-0440

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Android versions Android-11
Description A missing permission check in the createVirtualDisplay function of DisplayManagerService.java could allow for the creation of a trusted virtual display. This issue may lead to local escalation of privilege without requiring additional execution privileges. User interaction is not necessary for exploitation.
Recommendations For Android version Android-11, apply the necessary patch or update to resolve the missing permission check issue in the createVirtualDisplay function of DisplayManagerService.java.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ASB-A-162627132
CVE-2020-0440

Affected Products

Android