Out of Bounds Read Vulnerability in Apusys by MediaTek
CVE-2021-0665
4.4MEDIUM
Summary
In MediaTek's Apusys, a vulnerability exists that allows for potential out of bounds read due to an incorrect bounds check. If exploited, this could lead to local information disclosure with system execution privileges required for exploitation. Notably, user interaction is not necessary for the attack to succeed, making it a significant concern for impacted systems. The issue has been identified with Patch ID: ALPS05672113, and remediation is recommended as detailed in the product security bulletin.
Affected Version(s)
MT6873, MT6875, MT6877, MT6883, MT6885, MT6889, MT6891, MT6893, MT8195, MT8791, MT8797, MT9636, MT9638, MT9639, MT9650, MT9652, MT9669, MT9686, MT9970, MT9980, MT9981 Android 10.0
References
CVSS V3.1
Score:
4.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved