← Vulnerability feed

Vulnerability record · CVE-2020-14123 · published 22 April 2022

CVE-2020-14123: Miui double free vulnerability

MMi · Miui

There is a pointer double free vulnerability in Some MIUI Services. When a function is called, the memory pointer is copied to two function modules, and an attacker can cause the pointer to be repeatedly released through malicious operations, resulting in the affected module crashing and affecting normal functionality, and if successfully exploited the vulnerability can cause elevation of privileges.

7.5 CVSS 3.1 High EPSS 0.93% · top 41.0% CWE-415 · Double free
7.5CVSS 3.1 base score, v2 5.0
0.93%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

There is a pointer double free vulnerability in Some MIUI Services. When a function is called, the memory pointer is copied to two function modules, and an attacker can cause the pointer to be repeatedly released through malicious operations, resulting in the affected module crashing and affecting normal functionality, and if successfully exploited the vulnerability can cause elevation of privileges.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-14123 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2020-14120Miui vulnerabilitySome Xiaomi models have a vulnerability in a certain application. The vulnerability is caused by the lack of checksum when using a three-party applic…EPSS 0.42%7.5CVE-2020-14127Miui out-of-bounds write vulnerabilityA denial of service vulnerability exists in some Xiaomi models of phones. The vulnerability is caused by heap overflow and can be exploited by attack…EPSS 1.0%7.5CVE-2020-14125Miui out-of-bounds read vulnerabilityA denial of service vulnerability exists in some Xiaomi models of phones. The vulnerability is caused by out-of-bound read/write and can be exploited…EPSS 7.3%5.5CVE-2020-14122Miui insufficient verification of data authenticity vulnerabilitySome Xiaomi phones have information leakage vulnerabilities, and some of them may be able to forge a specific identity due to the lack of parameter v…EPSS 0.16%5.5CVE-2020-14105Miui vulnerabilityThe application in the mobile phone can read the SNO information of the device, Xiaomi 10 MIUI < 2020.01.15.EPSS 0.26%5.5CVE-2020-14103Miui vulnerabilityThe application in the mobile phone can read the SNO information of the device, Xiaomi 10 MIUI < 2020.01.15.EPSS 0.70%5.5CVE-2020-14106Miui incorrect authorization vulnerabilityThe application in the mobile phone can unauthorized access to the list of running processes in the mobile phone, Xiaomi Mobile Phone MIUI < 2021.01.…EPSS 0.66%9.8CVE-2026-33824Double free in Windows IKE Extension enables remote code executionA double free flaw (CWE-415) exists in the Windows IKE Extension, reachable over the network by an unauthenticated attacker. Successful exploitation …KEVEPSS 1.6%analysed

Source: NIST National Vulnerability Database (record CVE-2020-14123), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.