PT-2023-4286 · Mediatek · Keyinstall
Published
2023-08-07
·
Updated
2023-08-09
·
CVE-2023-20783
CVSS v3.1
6.7
Medium
| Vector | AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
keyinstall component of MediaTek microprogram software (affected versions not specified)
Description
The issue is related to insufficient input validation in the keyinstall component, which can lead to a possible out of bounds write due to a missing bounds check. This could allow an attacker to escalate their privileges locally with System execution privileges needed. User interaction is not required for exploitation.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Memory Corruption
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Keyinstall