Memory Corruption Issue in imgsys by MediaTek
CVE-2023-20803
6.5MEDIUM
Key Information:
- Vendor
- MediaTek
- Vendor
- CVE Published:
- 7 August 2023
Summary
In the imgsys component provided by MediaTek, a potential memory corruption vulnerability has been identified due to improper input validation. This flaw could allow an attacker to gain local escalation of privileges, requiring system execution rights. Exploitation of this vulnerability necessitates user interaction, making it vital for users to remain vigilant. A patch has been released to address this impact, detailed in the corresponding security bulletin.
Affected Version(s)
MT2713, MT6879, MT6895, MT6983, MT8188, MT8195, MT8395, MT8673 Android 12.0, 13.0 / IOT-v23.0 (Yocto 4.0)
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved