← Vulnerability feed

Vulnerability record · CVE-2020-0069 · published 10 March 2020

CVE-2020-0069: MediaTek Command Queue driver out-of-bounds write in Android kernel

Google · Android

The ioctl handlers in the MediaTek Command Queue driver fail to sanitize input and lack SELinux restrictions, allowing an out-of-bounds write in the Android kernel. Because the flaw is reachable locally with low privileges and no user interaction, it is a practical path to kernel-level privilege escalation on affected MediaTek-based Android devices.

7.8 CVSS 3.1 High CISA KEV since 3 Nov 2021 EPSS 1.4% · top 29.2% CWE-787 · Out-of-bounds write
7.8CVSS 3.1 base score, v2 7.2
1.4%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
29Affected product versions listed by NVD
5References
17 Jun 2026Last modified by NVD

Description

In the ioctl handlers of the Mediatek Command Queue driver, there is a possible out of bounds write due to insufficient input sanitization and missing SELinux restrictions. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-147882143References: M-ALPS04356754

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityCISA KEV listing confirms active exploitation, and the flaw yields kernel privilege escalation, though it requires local access and low privileges.

What it is

The ioctl handlers in the MediaTek Command Queue driver fail to sanitize input and lack SELinux restrictions, allowing an out-of-bounds write in the Android kernel. Because the flaw is reachable locally with low privileges and no user interaction, it is a practical path to kernel-level privilege escalation on affected MediaTek-based Android devices.

Impact

An attacker with local access and low privileges gains kernel code execution, leading to full device compromise and potential persistent control.

Attack surface

Reached locally through ioctl calls to the MediaTek Command Queue driver; no user interaction is required and only low privileges are needed per the CVSS vector (AV:L/PR:L/UI:N).

Exploitation

CVE-2020-0069 is listed in CISA KEV with a 2021-11-03 addition date, confirming in-the-wild exploitation; EPSS 30-day probability is 0.0137 (70.5th percentile). No ransomware campaign use is documented.

What to do

  • Apply the Android security bulletin 2020-03-01 and vendor (Google, Huawei) updates for affected devices.
  • Restrict or remove access to the MediaTek Command Queue driver ioctl interface where feasible.
  • Enforce SELinux policy to block unprivileged access to the driver.
  • Track device firmware versions against the listed Huawei and Android product models and prioritize unpatched units.

Detection

  • Monitor for anomalous ioctl calls to the MediaTek Command Queue driver from low-privilege processes.
  • Audit SELinux denials and policy bypass attempts involving the command queue device node.
  • Watch for unexpected kernel crashes or memory corruption indicators on affected MediaTek devices.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2020-0069 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Mediatek Multiple Chipsets Insufficient Input Validation Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.

Affected products

29 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-0069 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2026-58704Android Cellular Modem improper authorization allows adjacent privilege escalationAndroid's Cellular Modem component contains a logic error that bypasses permission checks, allowing an attacker within radio/adjacent range to escala…KEVEPSS 0.59%analysed8.8CVE-2025-48543Android use-after-free allows Chrome sandbox escape to system_serverA use-after-free in multiple Android locations lets an attacker escape the Chrome sandbox and reach the Android system_server process. Because the fl…KEVEPSS 0.54%analysed8.4CVE-2025-48595Android Framework integer overflow enables local code executionAn integer overflow in multiple locations of the Android Framework can be turned into code execution. It allows a local attacker to escalate privileg…KEVEPSS 1.7%analysed7.8CVE-2025-48572Android Framework permissions bypass enables background activity launchMultiple locations in the Android Framework allow activities to be launched from the background because of a permissions bypass, a missing authentica…KEVEPSS 0.26%analysed7.8CVE-2024-32896Android Pixel logic error allows local privilege escalationCVE-2024-32896 is a logic error in Android (CWE-670/CWE-783) that permits a local attacker to bypass intended restrictions and escalate privileges. I…KEVEPSS 3.0%analysed7.8CVE-2024-29748Android Pixel logic error allows local privilege escalationCVE-2024-29748 is a logic error in Android code that permits bypassing a security check, leading to local escalation of privilege. It affects Google …KEVEPSS 0.67%analysed7.8CVE-2023-35674Android WindowState logic error allows background activity launch and privilege escalationA logic error in onCreate of WindowState.java in the Android Framework lets a background activity be launched, enabling local escalation of privilege…KEVEPSS 2.6%analysed7.8CVE-2023-20963Android WorkSource parcel mismatch local privilege escalationCVE-2023-20963 is a parcel mismatch in Android's WorkSource component that allows a local attacker to escalate privileges without additional executio…KEVEPSS 1.5%analysed

Source: NIST National Vulnerability Database (record CVE-2020-0069), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.