CVE-2020-0009
23Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 0.7%
from disclosure to weapon6 days
Published on NVDJan 8
1st PoC+6d
exploitation probability
0.7%top 50% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
In calc_vm_may_flags of ashmem.c, there is a possible arbitrary write to shared memory due to a permissions bypass. This could lead to local escalation of privilege by corrupting memory shared between processes, with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android kernel Android ID: A-142938932
Affected products
n/a · Androidpublic PoCs found — 2✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/47921cve_referencepacketstormsecurity.com/files/155903/Android-ashmem-Read-Only-Bypasses.htmlunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.