Out of Bounds Write in imgsys Affects MediaTek Products
CVE-2023-20805

6.7MEDIUM

Key Information:

Summary

The imgsys component in MediaTek products has a significant vulnerability that allows for a potential out of bounds write. This issue arises from a missing bounds check within the system, enabling local escalation of privileges. Critical system execution privileges are necessary for exploitation, and notably, no user interaction is required to trigger this vulnerability. MediaTek has released a patch, identified as ALPS07199773, to mitigate this risk.

Affected Version(s)

MT2713, MT6879, MT6895, MT6983, MT8188, MT8195, MT8395, MT8673 Android 12.0, 13.0 / IOT-v23.0 (Yocto 4.0)

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.