Possible Escalation of Privilege Due to Improper Certificate Validation
CVE-2024-20080
Currently unrated
Key Information:
- Vendor
- MediaTek
- Vendor
- CVE Published:
- 1 July 2024
Summary
In gnss service, there is a possible escalation of privilege due to improper certificate validation. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08720039; Issue ID: MSV-1424.
Affected Version(s)
MT2735, MT2737, MT6761, MT6765, MT6768, MT6781, MT6785, MT6789, MT6833, MT6853, MT6853T, MT6855, MT6873, MT6875, MT6877, MT6879, MT6880, MT6883, MT6885, MT6886, MT6889, MT6890, MT6891, MT6893, MT6895, MT6980, MT6983, MT6985, MT6989, MT6990, MT8666, MT8667, MT8673, MT8676, MT8678 Android 13.0, 14.0 / Yocto 2.6, 3.3, 4.0 / RDK-B 22Q3
References
Timeline
Vulnerability published
Vulnerability Reserved