Vulnerability record · CVE-2020-0069 · published 10 March 2020
CVE-2020-0069: MediaTek Command Queue driver out-of-bounds write in Android kernel
Google · Android
The ioctl handlers in the MediaTek Command Queue driver fail to sanitize input and lack SELinux restrictions, allowing an out-of-bounds write in the Android kernel. Because the flaw is reachable locally with low privileges and no user interaction, it is a practical path to kernel-level privilege escalation on affected MediaTek-based Android devices.
Description
In the ioctl handlers of the Mediatek Command Queue driver, there is a possible out of bounds write due to insufficient input sanitization and missing SELinux restrictions. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-147882143References: M-ALPS04356754
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCISA KEV listing confirms active exploitation, and the flaw yields kernel privilege escalation, though it requires local access and low privileges.
What it is
The ioctl handlers in the MediaTek Command Queue driver fail to sanitize input and lack SELinux restrictions, allowing an out-of-bounds write in the Android kernel. Because the flaw is reachable locally with low privileges and no user interaction, it is a practical path to kernel-level privilege escalation on affected MediaTek-based Android devices.
Impact
An attacker with local access and low privileges gains kernel code execution, leading to full device compromise and potential persistent control.
Attack surface
Reached locally through ioctl calls to the MediaTek Command Queue driver; no user interaction is required and only low privileges are needed per the CVSS vector (AV:L/PR:L/UI:N).
Exploitation
CVE-2020-0069 is listed in CISA KEV with a 2021-11-03 addition date, confirming in-the-wild exploitation; EPSS 30-day probability is 0.0137 (70.5th percentile). No ransomware campaign use is documented.
What to do
- Apply the Android security bulletin 2020-03-01 and vendor (Google, Huawei) updates for affected devices.
- Restrict or remove access to the MediaTek Command Queue driver ioctl interface where feasible.
- Enforce SELinux policy to block unprivileged access to the driver.
- Track device firmware versions against the listed Huawei and Android product models and prioritize unpatched units.
Detection
- Monitor for anomalous ioctl calls to the MediaTek Command Queue driver from low-privilege processes.
- Audit SELinux denials and policy bypass attempts involving the command queue device node.
- Watch for unexpected kernel crashes or memory corruption indicators on affected MediaTek devices.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2020-0069 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Mediatek Multiple Chipsets Insufficient Input Validation Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.
Affected products
29 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200527-01-mtk-en | Vendor Advisory |
| https://source.android.com/security/bulletin/2020-03-01 | Vendor Advisory |
| http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200527-01-mtk-en | Vendor Advisory |
| https://source.android.com/security/bulletin/2020-03-01 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-0069 | Third Party AdvisoryUS Government Resource |
Track CVE-2020-0069 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-0069), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.