cve/2020/CVE-2020-8913.md

40 lines
2.3 KiB
Markdown
Raw Normal View History

2024-05-25 21:48:12 +02:00
### [CVE-2020-8913](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8913)
![](https://img.shields.io/static/v1?label=Product&message=Android%20Play%20Core&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=stable%3C%201.7.2%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-281%20Improper%20Preservation%20of%20Permissions&color=brighgreen)
### Description
A local, arbitrary code execution vulnerability exists in the SplitCompat.install endpoint in Android's Play Core Library versions prior to 1.7.2. A malicious attacker could create an apk which targets a specific application, and if a victim were to install this apk, the attacker could perform a directory traversal, execute code as the targeted application and access the targeted application's data on the Android device. We recommend all users update Play Core to version 1.7.2 or later.
### POC
#### Reference
- https://blog.oversecured.com/Oversecured-automatically-discovers-persistent-code-execution-in-the-Google-Play-Core-Library/
2024-06-09 00:33:16 +00:00
- https://blog.oversecured.com/Oversecured-automatically-discovers-persistent-code-execution-in-the-Google-Play-Core-Library/
2024-05-25 21:48:12 +02:00
#### Github
- https://github.com/0xSojalSec/android-security-resource
- https://github.com/0xsaju/awesome-android-security
- https://github.com/ARPSyndicate/cvemon
- https://github.com/B3nac/Android-Reports-and-Resources
- https://github.com/CyberLegionLtd/awesome-android-security
- https://github.com/Live-Hack-CVE/CVE-2020-8913
- https://github.com/Mehedi-Babu/mobile_sec_cyber
- https://github.com/Saidul-M-Khan/Awesome-Android-Security
- https://github.com/Swordfish-Security/awesome-android-security
- https://github.com/albinjoshy03/4NdrO1D
- https://github.com/annapustovaya/Mobix
- https://github.com/ctflearner/Learn365
- https://github.com/drerx/Android-Reports-and-Resources
- https://github.com/followboy1999/androidpwn
- https://github.com/noname1007/awesome-mobile-security
- https://github.com/paulveillard/cybersecurity-mobile-security
- https://github.com/rajbhx/Awesome-Android-Security-Clone
- https://github.com/retr0-13/awesome-android-security
- https://github.com/saeidshirazi/awesome-android-security
- https://github.com/son-of-win/Android-pentest
- https://github.com/vaib25vicky/awesome-mobile-security
- https://github.com/vickyke1/Android-Reports-and-Resources.