CVE-2020-8899
There is a buffer overwrite vulnerability in the Quram qmg library of Samsung's Android OS versions O(8.x), P(9.0) and Q(10.0).
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (5.76%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
There is a buffer overwrite vulnerability in the Quram qmg library of Samsung's Android OS versions O(8.x), P(9.0) and Q(10.0). An unauthenticated, unauthorized attacker sending a specially crafted MMS to a vulnerable phone can trigger a heap-based buffer overflow in the Quram image codec leading to an arbitrary remote code execution (RCE) without any user interaction. The Samsung ID is SVE-2020-16747.
- CVSS 4.0
- 10.0 CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 5.76% probability · 93th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-122, CWE-787
- Affected
- google/android
- Source
- cve-coordination@google.com
References
- http://packetstormsecurity.com/files/157620/Samsung-Android-Remote-Code-Execution.htmlThird Party Advisory, VDB Entry
- https://bugs.chromium.org/p/project-zero/issues/detail?id=2002Exploit, Issue Tracking, Third Party Advisory
- https://security.samsungmobile.com/securityUpdate.smsbVendor Advisory
- https://www.kb.cert.org/vuls/id/366027Third Party Advisory, US Government Resource
- http://packetstormsecurity.com/files/157620/Samsung-Android-Remote-Code-Execution.htmlThird Party Advisory, VDB Entry
- https://bugs.chromium.org/p/project-zero/issues/detail?id=2002Exploit, Issue Tracking, Third Party Advisory
- https://security.samsungmobile.com/securityUpdate.smsbVendor Advisory
- https://www.kb.cert.org/vuls/id/366027Third Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.