Use After Free Vulnerability in Mediatek VDEC Product
CVE-2023-20685
6.4MEDIUM
Key Information:
- Vendor
MediaTek
- Vendor
- CVE Published:
- 6 April 2023
What is CVE-2023-20685?
A vulnerability exists in Mediatek's VDEC that allows for a use after free condition due to a race condition. This flaw can lead to local privilege escalation, granting the attacker System execution privileges without requiring user interaction. It is crucial for users of the affected VDEC versions to apply the relevant patches to protect against potential exploitation.
Affected Version(s)
MT6789, MT6855, MT6879, MT6895, MT6983, MT8673, MT8781, MT8795T, MT8798, MT8891 Android 12.0, 13.0