Improper Authentication in Microsoft Your Phone Companion App for Android - CVE-2020-0943

 

Improper Authentication in Microsoft Your Phone Companion App for Android - CVE-2020-0943

Published: April 14, 2020


Vulnerability identifier: #VU26865
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-0943
CWE-ID: CWE-287
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to bypass authentication process.

The vulnerability exists in Microsoft YourPhoneCompanion application for Android, in the way the application processes notifications generated by work profiles. An attacker with physical access to the device can bypass authentication process and view notifications.


Affected software

Microsoft Your Phone Companion App for Android

How to mitigate CVE-2020-0943

Install updates from vendor's website.


External References

Related Security Bulletins