Memory Corruption Vulnerability in MediaTek's Secmem Component
CVE-2023-32834
Key Information:
- Vendor
- MediaTek
- Vendor
- CVE Published:
- 6 November 2023
Summary
A memory corruption issue exists in MediaTek's Secmem component due to type confusion, potentially allowing an attacker to escalate privileges to system execution levels. This vulnerability does not require any user interaction for exploitation and poses significant security risks. The associated patch is identified as ALPS08161762. It is crucial for users and administrators to apply the necessary updates to mitigate any potential threats.
Affected Version(s)
MT6580, MT6735, MT6737, MT6739, MT6753, MT6761, MT6765, MT6768, MT6771, MT6779, MT6781, MT6785, MT6789, MT6833, MT6835, MT6853, MT6853T, MT6855, MT6873, MT6877, MT6879, MT6883, MT6885, MT6886, MT6889, MT6893, MT6895, MT6983, MT6985, MT8185, MT8321, MT8385, MT8666, MT8667, MT8673, MT8675, MT8765, MT8766, MT8768, MT8781, MT8786, MT8788, MT8789, MT8791, MT8791T, MT8797, MT8798 Android 11.0, 12.0, 13.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved