Security Features in OneDrive for Android - CVE-2020-0654

 

Security Features in OneDrive for Android - CVE-2020-0654

Published: January 14, 2020


Vulnerability identifier: #VU24264
CSH Severity: Low
CVSS v4: 7 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-0654
CWE-ID: CWE-254
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

This vulnerability allows a local attacker to bypass security rescritions feature.

The vulnerability exists due to the way Microsoft OneDrive App for Android handles sharing links. An attacker with physical access can bypass the passcode or fingerprint requirements of the App.


Affected software

OneDrive for Android

How to mitigate CVE-2020-0654

Install updates from vendor's website.


External References

Related Security Bulletins