PT-2023-17561 · Mediatek · Preloader
Published
2023-05-15
·
Updated
2025-01-23
·
CVE-2023-20695
CVSS v3.1
6.7
Medium
| Vector | AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
preloader versions for MT6880, MT6890, MT6980, and MT6990
Description
The issue is caused by a missing bounds check, leading to a possible out of bounds write in the preloader. This could result in local escalation of privilege, requiring System execution privileges. User interaction is not needed for exploitation.
Recommendations
For preloader versions for MT6880, MT6890, MT6980, and MT6990, apply the patch with ID ALPS07734012 or ALPS07874363 to resolve the issue.
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Preloader