Possible Escalation of Privilege via Permissions Bypass
CVE-2024-20015

7.8HIGH

Summary

A vulnerability exists within MediaTek's telephony products that facilitates a local escalation of privilege due to a permissions bypass. This flaw allows attackers to gain higher privileges on the system without the necessity for additional execution privileges or user interaction. The issue highlights the importance of maintaining stringent security measures in telephony applications, especially in environments where comprehensive access controls are expected. The identified patch for this vulnerability is coded ALPS08441419. For more details on the patch and security guidelines, refer to the official MediaTek product security bulletin.

Affected Version(s)

MT6739, MT6753, MT6757, MT6761, MT6762, MT6763, MT6765, MT6768, MT6769, MT6781, MT6833, MT6835, MT6853, MT6855, MT6873, MT6875, MT6877, MT6879, MT6883, MT6885, MT6886, MT6889, MT6893, MT6895, MT6983, MT6985, MT8321, MT8667, MT8673, MT8765, MT8766, MT8768, MT8781, MT8786, MT8788, MT8789, MT8791T, MT8797, MT8798 Android 12.0, 13.0, 14.0

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.