CVE-2020-8913 Vulnerability Details

  /     /     /  

CVE-2020-8913 Metadata Quick Info

CVE Published: 12/08/2020 | CVE Updated: 04/08/2024 | CVE Year: 2020
Source: Google | Vendor: Google LLC | Product: Android Play Core
Status : PUBLISHED

CVE-2020-8913 Description

A local, arbitrary code execution vulnerability exists in the SplitCompat.install endpoint in Android\'s Play Core Library versions prior to 1.7.2. A malicious attacker could create an apk which targets a specific application, and if a victim were to install this apk, the attacker could perform a directory traversal, execute code as the targeted application and access the targeted application\'s data on the Android device. We recommend all users update Play Core to version 1.7.2 or later.

Metrics

CVSS Version: 3.1 | Base Score: 8.8 HIGH
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

l➤ Exploitability Metrics:
    Attack Vector (AV)* NETWORK
    Attack Complexity (AC)* LOW
    Privileges Required (PR)* NONE
    User Interaction (UI)* REQUIRED
    Scope (S)* UNCHANGED

l➤ Impact Metrics:
    Confidentiality Impact (C)* HIGH
    Integrity Impact (I)* HIGH
    Availability Impact (A)* HIGH

Weakness Enumeration (CWE)

CWE-ID: CWE-281
CWE Name: CWE-281 Improper Preservation of Permissions
Source: Google LLC

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).