CVE-2020-0440 describes a local escalation of privilege vulnerability in Android 11, specifically within the DisplayManagerService.java component. A missing permission check in the createVirtualDisplay function allows an attacker to create a trusted virtual display, bypassing security controls. This flaw carries a high CVSS score of 7.8, indicating a significant impact with high confidentiality, integrity, and availability compromise, requiring no user interaction or additional execution privileges. While it has a low EPSS score and is not listed in KEV, there is no public exploit code available, and community discussion and media coverage are minimal, suggesting limited active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
11.0CPE matchmatch criteria | cpe:2.3:o:google:android:11.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.