Security Features in OneDrive for Android - CVE-2020-0654

 

Security Features in OneDrive for Android - CVE-2020-0654

Published: January 14, 2020


Vulnerability identifier: #VU24264
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2020-0654
CWE-ID: CWE-254
Exploitation vector: Local access
Exploit availability: No public exploit available
Vendor: Microsoft
Affected software:
OneDrive for Android

Detailed vulnerability description

This vulnerability allows a local attacker to bypass security rescritions feature.

The vulnerability exists due to the way Microsoft OneDrive App for Android handles sharing links. An attacker with physical access can bypass the passcode or fingerprint requirements of the App.


How to mitigate CVE-2020-0654

Install updates from vendor's website.

Sources