Out of Bounds Write Vulnerability in MediaTek VDEC
CVE-2023-32848

6.7MEDIUM

Key Information:

Summary

The MediaTek VDEC has a vulnerability that allows for a possible out of bounds write due to a type confusion issue. This could potentially result in local escalation of privilege where system execution rights may be obtained. Importantly, the exploitation of this vulnerability does not require user interaction, making it a significant concern for affected systems. MediaTek has issued a patch to address this issue, ensuring that users are able to secure their systems against potential threats.

Affected Version(s)

MT6761, MT6763, MT6765, MT6768, MT6771, MT6779, MT6785, MT6853, MT6873, MT6885 Android 11.0, 12.0, 13.0

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.