Improper Neutralization of Special Elements in Output Used by a Downstream Component in Google products - CVE-2020-12753

 

Improper Neutralization of Special Elements in Output Used by a Downstream Component in Google products - CVE-2020-12753

Published: June 3, 2020


Vulnerability identifier: #VU28535
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-12753
CWE-ID: CWE-74
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the system.

The vulnerability exists due to improper validation of input in the bootloader. A remote attacker can execute arbitrary code on the system.

Note: The LG ID is LVE-SMP-200006


Affected software

LG Q6
LG CV7
LG CV5
LG CV3
LG CV1
LG X cam
LG X500
LG X400
LG X300
LG Q8
LG CV1S
LG V60
LG V50
LG V40
LG V35
LG V30
LG V20
LG G8
LG G7
LG G6
LG CV7AS
LG DH50
LG DH5
LG DH40
LG DH35
LG DH30
LG DH15
LG DH10
LG Q70
LG Q60
LG K50
LG K40
LG K30
LG K20
Google Android

How to mitigate CVE-2020-12753

Install updates from vendor's website.


Links to Public Exploits and PoC-codes

External References

Related Security Bulletins