CVE-2020-8899 CRITICAL

CVE-2020-8899: Memory corruption in Quram library when decoding qmg can lead to RCE

Vendor Samsung
Product Android OS
Weakness CWE-122
Published May 6, 2020
Last update September 17, 2024

CVSS base score

10.0/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L

What the vulnerability does

01Description

There is a buffer overwrite vulnerability in the Quram qmg library of Samsung's Android OS versions O(8.x), P(9.0) and Q(10.0). An unauthenticated, unauthorized attacker sending a specially crafted MMS to a vulnerable phone can trigger a heap-based buffer overflow in the Quram image codec leading to an arbitrary remote code execution (RCE) without any user interaction. The Samsung ID is SVE-2020-16747.

Key dates

02Disclosure timeline

May 6, 2020 CVE published
September 17, 2024 Record updated