Out of Bounds Read Vulnerability in MediaTek KeyInstall Software
CVE-2023-20708
Key Information:
- Vendor
MediaTek
- Vendor
- CVE Published:
- 15 May 2023
What is CVE-2023-20708?
An out of bounds read vulnerability in MediaTek's KeyInstall could potentially allow local escalation of privileges due to a missing bounds check. This issue does not require user interaction for exploitation, granting attackers elevated System execution privileges. A patch has been released as part of ALPS07581655 to remediate this critical security concern.
Affected Version(s)
MT6580, MT6731, MT6735, MT6737, MT6739, MT6753, MT6757, MT6757C, MT6757CD, MT6757CH, MT6761, MT6762, MT6763, MT6765, MT6768, MT6769, MT6771, MT6779, MT6781, MT6785, MT6789, MT6833, MT6853, MT6853T, MT6855, MT6873, MT6875, MT6877, MT6879, MT6883, MT6885, MT6889, MT6891, MT6893, MT6895, MT6983, MT8185, MT8321, MT8385, MT8666, MT8667, MT8765, MT8766, MT8768, MT8781, MT8786, MT8788, MT8789, MT8791, MT8791T, MT8797 Android 11.0, 12.0, 13.0