Memory Corruption Vulnerability in Apusys by MediaTek
CVE-2021-0679

6.7MEDIUM

Key Information:

Summary

A vulnerability in Apusys from MediaTek allows for memory corruption due to a missing bounds check. This defect can potentially enable a local attacker to escalate privileges to system level without requiring any user interaction. Patches have been issued under Patch ID: ALPS05672107 addressing this issue.

Affected Version(s)

MT6873, MT6875, MT6877, MT6883, MT6885, MT6889, MT6891, MT6893, MT8195, MT8791, MT8797 Android 10.0, 11.0, 12.0

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.