Memory Corruption Vulnerability in Apusys Affects MediaTek Products
CVE-2021-0669
6.7MEDIUM
Summary
A vulnerability in the Apusys component of MediaTek products allows for memory corruption due to a use after free scenario. This flaw enables local escalation of privileges, requiring system execution rights for exploitation. Notably, user interaction is not necessary for an attacker to execute the exploit, making this a significant security concern. MediaTek has addressed this issue in patch ID ALPS05681550.
Affected Version(s)
MT6853, MT6853T, MT6873, MT6875, MT6877, MT6883, MT6885, MT6889, MT6891, MT6893, MT8195, MT8791, MT8797, MT9636, MT9638, MT9639, MT9650, MT9652, MT9669, MT9686, MT9970, MT9980, MT9981 Android 10.0, 11.0
References
CVSS V3.1
Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved