PT-2023-17561 · Mediatek · Preloader

Published

2023-05-15

·

Updated

2025-01-23

·

CVE-2023-20695

CVSS v3.1

6.7

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions preloader versions for MT6880, MT6890, MT6980, and MT6990
Description The issue is caused by a missing bounds check, leading to a possible out of bounds write in the preloader. This could result in local escalation of privilege, requiring System execution privileges. User interaction is not needed for exploitation.
Recommendations For preloader versions for MT6880, MT6890, MT6980, and MT6990, apply the patch with ID ALPS07734012 or ALPS07874363 to resolve the issue.

Fix

Memory Corruption

Weakness Enumeration

Related Identifiers

ASB-A-271788841
CVE-2023-20695
M-ALPS07734012

Affected Products

Preloader