Out of Bounds Write Vulnerability in V5 DA Affected by MediaTek
CVE-2024-20141

6.6MEDIUM

Summary

In V5 DA, a vulnerability exists that allows for potential out of bounds writing. This flaw arises from inadequate bounds checking, which presents a risk of local escalation of privilege if an attacker has physical access to the device. Exploitation requires user interaction and does not necessitate any additional execution privileges. It is crucial for users to remain vigilant and apply available patches, such as Patch ID ALPS09291402, to mitigate this security issue.

Affected Version(s)

MT6739, MT6761, MT6765, MT6768, MT6771, MT6779, MT6781, MT6785, MT6833, MT6853, MT6873, MT6877, MT6885, MT6893, MT8167, MT8167S, MT8175, MT8185, MT8195, MT8321, MT8362A, MT8365, MT8385, MT8395, MT8666, MT8667, MT8673, MT8675, MT8678, MT8765, MT8766, MT8768, MT8771, MT8775, MT8781, MT8786, MT8788, MT8789, MT8791T, MT8795T, MT8797, MT8798, MT8893 Android 12.0, 13.0, 14.0, 15.0

References

CVSS V3.1

Score:
6.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.