Out of Bounds Write Vulnerability in MediaTek VDEC
CVE-2023-32848
6.7MEDIUM
Key Information:
- Vendor
- MediaTek
- Vendor
- CVE Published:
- 4 December 2023
Summary
The MediaTek VDEC has a vulnerability that allows for a possible out of bounds write due to a type confusion issue. This could potentially result in local escalation of privilege where system execution rights may be obtained. Importantly, the exploitation of this vulnerability does not require user interaction, making it a significant concern for affected systems. MediaTek has issued a patch to address this issue, ensuring that users are able to secure their systems against potential threats.
Affected Version(s)
MT6761, MT6763, MT6765, MT6768, MT6771, MT6779, MT6785, MT6853, MT6873, MT6885 Android 11.0, 12.0, 13.0
References
CVSS V3.1
Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved