PT-2020-2288 · Microsoft · Yourphonecompanion

Published

2020-04-14

·

Updated

2021-07-21

·

CVE-2020-0943

CVSS v2.0

4.9

Medium

VectorAV:L/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Microsoft YourPhoneCompanion application for Android (affected versions not specified)
Description The issue is related to an authentication bypass in the way the application processes notifications generated by work profiles. This could allow an unauthenticated attacker to view notifications. The vulnerability is also associated with deficiencies in the authentication procedure, which could enable an attacker to gain unauthorized access to protected information and elevate their privileges.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-02240
CVE-2020-0943

Affected Products

Yourphonecompanion