Potential Out of Bounds Write Vulnerability in MediaTek Key Management Component
CVE-2023-20751
6.7MEDIUM
Key Information:
- Vendor
- MediaTek
- Vendor
- CVE Published:
- 6 June 2023
Summary
A vulnerability exists in the key management component of MediaTek products, where a missing bounds check can lead to an out of bounds write condition. This security flaw may allow an attacker to escalate privileges locally, gaining system execution capabilities without needing user interaction. Remediation is available through a dedicated patch from MediaTek.
Affected Version(s)
MT8167, MT8167S, MT8168, MT8175, MT8195, MT8362A, MT8365 Android 12.0, 13.0
References
CVSS V3.1
Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved