SB2020011427 - Security feature bypass in Microsoft OneDrive for Android
Published: January 14, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Security Features (CVE-ID: CVE-2020-0654)
This vulnerability allows a local attacker to bypass security rescritions feature.
The vulnerability exists due to the way Microsoft OneDrive App for Android handles sharing links. An attacker with physical access can bypass the passcode or fingerprint requirements of the App.
Remediation
Install update from vendor's website.