Security Features in OneDrive for Android - CVE-2020-0654
Published: January 14, 2020
Vulnerability identifier: #VU24264
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2020-0654
CWE-ID: CWE-254
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vendor: Microsoft
Affected software:
OneDrive for Android
OneDrive for Android
Detailed vulnerability description
This vulnerability allows a local attacker to bypass security rescritions feature.
The vulnerability exists due to the way Microsoft OneDrive App for Android handles sharing links. An attacker with physical access can bypass the passcode or fingerprint requirements of the App.
How to mitigate CVE-2020-0654
Install updates from vendor's website.