Security Features in OneDrive for Android - CVE-2020-0654
Published: January 14, 2020
Vulnerability identifier: #VU24264
CSH Severity: Low
CVSS v4: 7 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-0654
CWE-ID: CWE-254
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
This vulnerability allows a local attacker to bypass security rescritions feature.
The vulnerability exists due to the way Microsoft OneDrive App for Android handles sharing links. An attacker with physical access can bypass the passcode or fingerprint requirements of the App.
Affected software
OneDrive for Android
How to mitigate CVE-2020-0654
Install updates from vendor's website.