Out of Bounds Write Vulnerability in Apusys by MediaTek
CVE-2021-0678
6.7MEDIUM
Summary
A vulnerability exists in Apusys, where a missing bounds check could allow an out of bounds write, potentially leading to local escalation of privileges. Importantly, exploitation does not require user interaction, making it particularly concerning for system security. The issue has been documented under Patch ID ALPS05672107 and Issue ID ALPS05722511, and users are urged to apply the appropriate security patches to mitigate any risks.
Affected Version(s)
MT6873, MT6875, MT6877, MT6883, MT6885, MT6889, MT6891, MT6893, MT8195, MT8791, MT8797 Android 10.0, 11.0, 12.0
References
CVSS V3.1
Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved