Out of Bounds Read in KeyInstall Affects MediaTek Products
CVE-2023-20711
Key Information:
- Vendor
MediaTek
- Vendor
- CVE Published:
- 15 May 2023
What is CVE-2023-20711?
The vulnerability resides in the KeyInstall component of MediaTek products, where a missing bounds check allows for an out of bounds read. This flaw can potentially expose sensitive local information without user interaction and could be exploited with system execution privileges. It is crucial for users to apply the patch ID ALPS07581668 to mitigate the risk associated with this issue.
Affected Version(s)
MT6580, MT6731, MT6735, MT6737, MT6739, MT6753, MT6757, MT6757C, MT6757CD, MT6757CH, MT6761, MT6762, MT6763, MT6765, MT6768, MT6769, MT6771, MT6779, MT6781, MT6785, MT6789, MT6833, MT6835, MT6853, MT6853T, MT6855, MT6873, MT6875, MT6877, MT6879, MT6883, MT6885, MT6886, MT6889, MT6891, MT6893, MT6895, MT6983, MT6985, MT8185, MT8321, MT8385, MT8666, MT8667, MT8765, MT8766, MT8768, MT8781, MT8786, MT8788, MT8789, MT8791, MT8791T, MT8797 Android 11.0, 12.0, 13.0