Out of Bounds Read in Keyinstall Affects MediaTek Products
CVE-2023-20709

4.4MEDIUM

What is CVE-2023-20709?

A significant vulnerability in MediaTek's keyinstall component allows for potential out of bounds read, which can lead to unauthorized local information disclosure. This security flaw arises from a missing bounds check, thereby enabling attackers to exploit the issue without requiring user interaction. The vulnerability necessitates system execution privileges for exploitation. Users and administrators should be aware of this issue and apply the necessary patches to mitigate risks. Further details can be found in MediaTek's product security bulletin.

Affected Version(s)

MT6580, MT6731, MT6735, MT6737, MT6739, MT6753, MT6757, MT6757C, MT6757CD, MT6757CH, MT6761, MT6762, MT6763, MT6765, MT6768, MT6769, MT6771, MT6779, MT6781, MT6785, MT6789, MT6833, MT6853, MT6853T, MT6855, MT6873, MT6875, MT6877, MT6879, MT6883, MT6885, MT6889, MT6891, MT6893, MT6895, MT6983, MT8185, MT8321, MT8385, MT8666, MT8667, MT8765, MT8766, MT8768, MT8781, MT8786, MT8788, MT8789, MT8791, MT8791T, MT8797 Android 11.0, 12.0, 13.0

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.