Out of Bounds Write Vulnerability in MediaTek Products
CVE-2023-20750

4.1MEDIUM

Summary

A vulnerability exists in MediaTek's SWPM due to a race condition that can lead to an out of bounds write. This flaw can allow an attacker to gain access to local information, requiring system execution privileges for exploitation. Importantly, user interaction is not required, making this a potential risk for systems running affected versions. Users and administrators are encouraged to apply the necessary patches to mitigate this risk.

Affected Version(s)

MT6835, MT6886, MT6983, MT6985, MT8167, MT8167S, MT8168, MT8175, MT8195, MT8321, MT8362A, MT8365, MT8385, MT8673, MT8765, MT8766, MT8768, MT8781, MT8786, MT8788, MT8791T, MT8797 Android 13.0

References

CVSS V3.1

Score:
4.1
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.