Vulnerability Description
MX Player Android App versions prior to v1.24.5, are vulnerable to a directory traversal vulnerability when user is using the MX Transfer feature in "Receive" mode. An attacker can exploit this by connecting to the MX Transfer session as a "sender" and sending a MessageType of "FILE_LIST" with a "name" field containing directory traversal characters (../). This will result in the file being transferred to the victim's phone, but being saved outside of the intended "/sdcard/MXshare" directory. In some instances, an attacker can achieve remote code execution by writing ".odex" and ".vdex" files in the "oat" directory of the MX Player application.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mxplayer | Mx Player | < 1.24.5 |
Related Weaknesses (CWE)
References
- https://www.tenable.com/security/research/tra-2020-41ExploitThird Party Advisory
- https://www.tenable.com/security/research/tra-2020-41ExploitThird Party Advisory
FAQ
What is CVE-2020-5764?
CVE-2020-5764 is a vulnerability with a CVSS score of 8.8 (HIGH). MX Player Android App versions prior to v1.24.5, are vulnerable to a directory traversal vulnerability when user is using the MX Transfer feature in "Receive" mode. An attacker can exploit this by con...
How severe is CVE-2020-5764?
CVE-2020-5764 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-5764?
Check the references section above for vendor advisories and patch information. Affected products include: Mxplayer Mx Player.