Out of Bounds Write Vulnerability in MediaTek KeyManagement Product
CVE-2023-20752
Key Information:
- Vendor
MediaTek
- Vendor
- CVE Published:
- 6 June 2023
What is CVE-2023-20752?
A vulnerability exists in MediaTek's KeyManagement product that allows for an out of bounds write due to missing bounds checks. This flaw can potentially lead to local privilege escalation with system-level execution privileges. Importantly, exploitation can occur without requiring user interaction, which heightens the risk of unauthorized access and control over vulnerable systems. MediaTek has acknowledged this issue and provided a patch under Patch ID: ALPS07826586, urging users to update their systems to mitigate this potential threat.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
MT8167, MT8167S, MT8168, MT8175, MT8195, MT8362A, MT8365 Android 12.0, 13.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
