SB2020011427 - Security feature bypass in Microsoft OneDrive for Android



SB2020011427 - Security feature bypass in Microsoft OneDrive for Android

Published: January 14, 2020

Security Bulletin ID SB2020011427
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Physical access
Highest impact Code execution

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Security Features (CVE-ID: CVE-2020-0654)

This vulnerability allows a local attacker to bypass security rescritions feature.

The vulnerability exists due to the way Microsoft OneDrive App for Android handles sharing links. An attacker with physical access can bypass the passcode or fingerprint requirements of the App.


Remediation

Install update from vendor's website.