CVE-2020-7744
This affects all versions of package com.mintegral.msdk:alphab. The Android SDK distributed by the company contains malicious functionality in this module that tracks: 1. Downloads from Google urls either within Google apps or via browser including file downloads, e-mail attachments and Google Docs links. 2. All apk downloads, either organic or not. Mintegral listens to download events in Android's download manager and detects if the downloaded file's url contains: a. google.com or comes from a Google app (the com.android.vending package) b.
Leer descripción completaMostrar menos
Ends with .apk for apk downloads In both cases, the module sends the captured data back to Mintegral's servers. Note that the malicious functionality keeps running even if the app is currently not in focus (running in the background).
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N
- Puntuación base: 4.7
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.86%
- Percentil entre todas las CVEs puntuadas: 57
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-319
Referencias
- https://snyk.io/blog/remote-code-execution-rce-sourmint/
- https://snyk.io/research/sour-mint-malicious-sdk/
- https://snyk.io/vuln/SNYK-JAVA-COMMINTEGRALMSDK-1018714
- https://snyk.io/blog/remote-code-execution-rce-sourmint/
- https://snyk.io/research/sour-mint-malicious-sdk/
- https://snyk.io/vuln/SNYK-JAVA-COMMINTEGRALMSDK-1018714
JSON original (NVD)
Mostrar
{
"id": "CVE-2020-7744",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4.3,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:P/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "MEDIUM",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "report@snyk.io",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 4.7,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 1.4,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "report@snyk.io",
"affectedData": [
{
"vendor": "n/a",
"product": "com.mintegral.msdk:alphab",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "unspecified",
"versionType": "custom"
}
]
}
]
}
],
"published": "2020-10-15T13:15:12.993",
"references": [
{
"url": "https://snyk.io/blog/remote-code-execution-rce-sourmint/",
"tags": [
"Technical Description",
"Third Party Advisory"
],
"source": "report@snyk.io"
},
{
"url": "https://snyk.io/research/sour-mint-malicious-sdk/",
"tags": [
"Technical Description",
"Third Party Advisory"
],
"source": "report@snyk.io"
},
{
"url": "https://snyk.io/vuln/SNYK-JAVA-COMMINTEGRALMSDK-1018714",
"tags": [
"Third Party Advisory"
],
"source": "report@snyk.io"
},
{
"url": "https://snyk.io/blog/remote-code-execution-rce-sourmint/",
"tags": [
"Technical Description",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://snyk.io/research/sour-mint-malicious-sdk/",
"tags": [
"Technical Description",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://snyk.io/vuln/SNYK-JAVA-COMMINTEGRALMSDK-1018714",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-319"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "This affects all versions of package com.mintegral.msdk:alphab. The Android SDK distributed by the company contains malicious functionality in this module that tracks: 1. Downloads from Google urls either within Google apps or via browser including file downloads, e-mail attachments and Google Docs links. 2. All apk downloads, either organic or not. Mintegral listens to download events in Android's download manager and detects if the downloaded file's url contains: a. google.com or comes from a Google app (the com.android.vending package) b. Ends with .apk for apk downloads In both cases, the module sends the captured data back to Mintegral's servers. Note that the malicious functionality keeps running even if the app is currently not in focus (running in the background)."
},
{
"lang": "es",
"value": "Esto afecta a todas las versiones del paquete com.mintegral.msdk:alphab. El SDK de Android distribuido por la empresa contiene una funcionalidad maliciosa en este módulo que rastrea: 1. Descargas desde las URL de Google ya sea dentro de las aplicaciones de Google o por medio del navegador, incluyendo las descargas de archivos, los archivos adjuntos de correo electrónico y los enlaces de Google Docs. 2. Todas las descargas de apk, ya sean orgánicas o no. Mintegral escucha los eventos de descarga en el administrador de descargas de Android y detecta si la URL del archivo descargado contiene: a. google.com o proviene de una aplicación de Google (el paquete com.android.vending) b. Termina con .apk para descargas de apk. En ambos casos, el módulo envía los datos capturados hacia los servidores de Mintegral. Tome en cuenta que la funcionalidad maliciosa sigue ejecutándose incluso si la aplicación no está actualmente enfocada (ejecutándose en segundo plano)"
}
],
"lastModified": "2026-06-17T03:25:22.080",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:mintegral:mintegraladsdk:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EA48ECCB-BEC3-452C-80EF-61C9C3A6DB22"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:google:android:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "F8B9FEC8-73B6-43B8-B24E-1F7C20D91D26"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "report@snyk.io"
}