Out of Bounds Write Vulnerability in MediaTek Audio Systems
CVE-2023-32847

7.8HIGH

Summary

This vulnerability in MediaTek audio systems occurs due to a missing bounds check, allowing a potential out of bounds write. Exploitation requires user interaction and can lead to a local escalation of privilege without the need for additional execution privileges. Mitigation strategies should be implemented promptly to enhance security against this vulnerability.

Affected Version(s)

MT2713, MT6580, MT6739, MT6761, MT6762, MT6765, MT6779, MT6785, MT6789, MT6833, MT6835, MT6853, MT6853T, MT6855, MT6873, MT6877, MT6879, MT6883, MT6885, MT6886, MT6889, MT6895, MT6983, MT6985, MT8167, MT8167S, MT8168, MT8175, MT8188, MT8195, MT8321, MT8362A, MT8365, MT8385, MT8390, MT8395, MT8765, MT8766, MT8768, MT8781, MT8786, MT8788, MT8789, MT8791T, MT8797, MT8798 Android 12.0, 13.0

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.