Memory Corruption Vulnerability in MediaTek Display DRM Products
CVE-2023-32885
Key Information:
- Vendor
- MediaTek
- Vendor
- CVE Published:
- 2 January 2024
Summary
A vulnerability has been identified within the MediaTek display DRM that allows for potential memory corruption due to an inadequately implemented bounds check. This flaw may facilitate local privilege escalation, enabling attackers to execute actions with elevated system-level privileges. Crucially, user interaction is not a prerequisite for exploitation, which heightens the risk associated with this vulnerability. MediaTek recommends applying the relevant security patch (ALPS07780685) to mitigate any potential threats.
Affected Version(s)
MT6761, MT6765, MT6768, MT6779, MT6781, MT6785, MT6789, MT6833, MT6835, MT6853, MT6855, MT6873, MT6877, MT6879, MT6883, MT6885, MT6886, MT6889, MT6893, MT6895, MT6983, MT6985, MT8168, MT8188, MT8195, MT8766, MT8768, MT8781, MT8789, MT8791T, MT8798 Android 12.0, 13.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved