VulnerabilityModified
CVE-2020-11875
The MTK kernel does not properly implement exception handling, allowing an attacker to gain privileges.
HIGH 7.8EPSS 0.18%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.18%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9.0, and 10.0 (MTK chipsets) software. The MTK kernel does not properly implement exception handling, allowing an attacker to gain privileges. The LG ID is LVE-SMP-200001 (February 2020).
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.18% probability · 8th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-755
- Affected
- google/android
- Source
- cve@mitre.org
References
- https://cwe.mitre.org/data/definitions/755.htmlThird Party Advisory
- https://lgsecurity.lge.com/Vendor Advisory
- https://cwe.mitre.org/data/definitions/755.htmlThird Party Advisory
- https://lgsecurity.lge.com/Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.