Local Privilege Escalation Vulnerability in Android Kernel by Google
CVE-2020-0423
7.8HIGH
Key Information:
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2020-0423?
A vulnerability exists within the Android kernel's binder subsystem, where improper locking in the binder_release_work function can result in a use-after-free condition. This flaw enables a local attacker to escalate their privileges on the device without requiring any additional execution permissions or user interaction. As such, it poses significant risks to the integrity and security of affected Android systems.
Affected Version(s)
Android Android kernel
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.