CVE-2020-0069
KEVmassOut-of-Bounds Write in MediaTek Command Queue Driver Enables Android Privilege Escalation
CISA: Mediatek Multiple Chipsets Insufficient Input Validation Vulnerability
CVE-2020-0069 is an out-of-bounds write (CWE-787) in the ioctl handlers of the MediaTek Command Queue kernel driver on Android, caused by insufficient input validation and missing SELinux restrictions. Any application running locally can trigger the flaw by sending maliciously crafted ioctl requests, and no special permissions or user interaction are required. A successful exploit corrupts kernel memory and achieves local escalation of privilege, giving the attacker root-level control of the device. Affected users are owners of Android phones built on the multiple MediaTek chipsets named by CISA, spanning Google Android and numerous Huawei/Honor firmware builds (including Honor 20 Pro, Nova 3, Y6 2019, and Berkeley/Columbia/Cornell/Dura firmware variants). The flaw is confirmed as exploited in the wild via CISA's KEV catalog (added 2021-11-03, with ransomware use listed as unknown), EPSS estimates a 1.4% probability of exploitation within 30 days, no public PoC is cataloged, and the KEV listing coincided with reports of rooting malware such as AbstractEmu capable of gaining root on Android devices.
What to do: Apply the latest vendor firmware / Android security update per vendor instructions, as required by the CISA KEV entry, and verify the device shows a current Android security patch level in Settings > About phone. Because exploitation requires a locally installed app, avoid installing untrusted or sideloaded apps on unpatched MediaTek-based devices as an interim mitigation. Organizations should inventory MediaTek-powered handsets, including the listed Huawei/Honor models, and prioritize patching them given confirmed in-the-wild exploitation.
| MediaTek | Chipset list not enumerated in source data; affected Android kernel builds fixed via vendor security updates |
| Google Android | Android kernel (affected Android release versions not enumerated in source data) |
| Huawei Berkeley-L09 firmware | — |
| Huawei Columbia-AL10B firmware | — |
| Huawei Columbia-L29D firmware | — |
| Huawei Columbia-TL00B firmware | — |
| Huawei Columbia-TL00D firmware | — |
| Huawei Cornell-AL00A firmware | — |
| Huawei Cornell-TL10B firmware | — |
| Huawei Dura-AL00A firmware | — |
| Huawei Honor 20 Pro firmware | — |
| Huawei Y6 2019 firmware | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
In the ioctl handlers of the Mediatek Command Queue driver, there is a possible out of bounds write due to insufficient input sanitization and missing SELinux restrictions. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-147882143References: M-ALPS04356754
- Affected
- MediaTek Multiple Chipsets
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- googlehuawei
- Products
- android, berkeley-l09 firmware, columbia-al10b firmware, columbia-l29d firmware, columbia-tl00b firmware, columbia-tl00d firmware, cornell-al00a firmware, cornell-tl10b firmware, dura-al00a firmware, honor 20 pro firmware, y6 2019 firmware, nova 3 firmware
- Weakness
- CWE-787
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H