CVE-2020-8936 is an arbitrary memory overwrite vulnerability in Google Asylo versions up to 0.6.0. An attacker can exploit this by making a host call to UntrustedCall, which fails to validate buffer ranges, allowing the host to return an enclave memory address. This medium-severity vulnerability (CVSS 5.5) allows an authenticated local attacker to read sensitive data from within the enclave. There is no public exploit code available, no evidence of active exploitation, and minimal community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.6.0CPE matchmatch criteria | cpe:2.3:a:google:asylo:*:*:*:*:*:*:*:* | ||
>= 0.6.0, <= 0.6.0CPE match | cpe:2.3:a:google:asylo:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.