Out of Bounds Write Vulnerability Affecting MediaTek's Display DRM
CVE-2023-32867

6.7MEDIUM

Summary

A vulnerability exists in MediaTek's Display DRM due to a missing bounds check, leading to a potential out of bounds write. This flaw enables local escalation of privileges, allowing an attacker to execute operations with elevated system privileges. The issue does not require user interaction for exploitation, making it a significant concern for affected systems. A patch has been released under ID ALPS07560793 to address this vulnerability.

Affected Version(s)

MT6761, MT6765, MT6768, MT6779, MT6781, MT6785, MT6789, MT6833, MT6835, MT6853, MT6855, MT6873, MT6877, MT6879, MT6883, MT6885, MT6886, MT6889, MT6893, MT6895, MT6983, MT6985, MT8188, MT8195, MT8673, MT8781 Android 12.0, 13.0

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.