PT-2024-18525 · Mediatek · Mt6Xxx+1
Published
2024-04-01
·
Updated
2025-04-23
·
CVE-2024-20040
CVSS v3.1
8.8
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
MT6XXX chipsets (affected versions not specified)
MT79XX chipsets (affected versions not specified)
Description
The issue is related to improper input validation in wlan firmware, leading to a possible out of bounds write. This could result in remote escalation of privilege without needing additional execution privileges. User interaction is not required for exploitation.
Recommendations
For MT6XXX chipsets, apply patch ID: ALPS08360153.
For MT79XX chipsets, apply patch ID: WCNCR00363530.
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mt6Xxx
Mt79Xx