Out of Bounds Write Vulnerability in MediaTek vdec Software
CVE-2023-20809

6.7MEDIUM

What is CVE-2023-20809?

The vdec software by MediaTek is susceptible to an out of bounds write due to insufficient bounds checking. This weakness can allow attackers to escalate privileges on local systems, potentially leading to unauthorized system execution. Importantly, user interaction is not required for exploitation, making this a significant risk for affected systems. It is crucial for users to apply the necessary patches to mitigate this vulnerability.

Affected Version(s)

MT5583, MT5691, MT5695, MT9010, MT9011, MT9012, MT9016, MT9020, MT9021, MT9022, MT9030, MT9031, MT9032, MT9215, MT9216, MT9218, MT9220, MT9221, MT9222, MT9255, MT9256, MT9266, MT9269, MT9285, MT9286, MT9288, MT9600, MT9602, MT9610, MT9611, MT9612, MT9613, MT9615, MT9617, MT9629, MT9630, MT9631, MT9632, MT9636, MT9638, MT9639, MT9650, MT9652, MT9666, MT9667, MT9669, MT9670, MT9671, MT9675, MT9685, MT9686, MT9688 Android 10.0, 11.0

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.