Out of Bounds Write in Mediatek Command System
CVE-2023-20850
Key Information:
- Vendor
MediaTek
- Vendor
- CVE Published:
- 4 September 2023
What is CVE-2023-20850?
The imgsys_cmdq module within Mediatek's architecture suffers from a vulnerability that allows for an out of bounds write due to inadequate range checking. This flaw could potentially be exploited by a local user to escalate privileges, requiring system execution rights for successful attacks. User interaction is necessary to trigger this vulnerability. Affected versions can be patched with the ID ALPS07340433 to mitigate the risk associated with this issue.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
MT2713, MT6895, MT6897, MT6983, MT8188, MT8195, MT8395, MT8781 Android 11.0, 12.0 / Linux 6.1 / IOT-v23.0 / Yocto 4.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
