PT-2024-18577 · Mediatek · Mediatek

Published

2024-10-06

·

Updated

2024-10-11

·

CVE-2024-20090

CVSS v3.1

6.7

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MediaTek products (affected versions not specified)
Description The issue is related to a possible out of bounds write in vdec due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not required for exploitation. Remediation is crucial, and users are urged to update to the latest firmware or apply the latest security patches to mitigate risks.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Memory Corruption

Weakness Enumeration

Related Identifiers

ASB-A-359692902
ASB-A-359699091
ASB-A-359699094
ASB-A-359699096
CVE-2024-20090
M-ALPS09028313

Affected Products

Mediatek