← Back

CVE-2019-20607

nvd nist
Published: Mar 24, 2020Modified: Jun 17, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) (MSM8996, MSM8998, Exynos7420, Exynos7870, Exynos8890, and Exynos8895 chipsets) software. A heap overflow in the keymaster Trustlet allows attackers to write to TEE memory, and achieve arbitrary code execution. The Samsung ID is SVE-2019-14126 (May 2019).

Affected (7)

Products: Google: Android
1 product
Android
Configuration A
7 vulnerable · 6 platform
Vulnerable SoftwareAffected Versions
Google
Version 7.0
Version 7.1.0
Version 7.1.1
Version 7.1.2
Version 8.0
Version 8.1
Version 9.0
Running on/withPlatform Versions
Qualcomm
Msm8996
All versions
Qualcomm
Msm8998
All versions
Samsung
Exynos 7420
All versions
Samsung
Exynos 7870
All versions
Samsung
Exynos 8890
All versions
Samsung
Exynos 8895
All versions

References (2)

Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.