PT-2024-18579 · Mediatek · Mediatek

Published

2024-10-06

·

Updated

2024-10-11

·

CVE-2024-20092

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MediaTek products (affected versions not specified)
Description A high-severity vulnerability affects MediaTek products, allowing for local escalation of privilege with System execution privileges needed. User interaction is not required for exploitation. The issue is due to a possible out of bounds write in vdec caused by a missing bounds check. Remediation is available, and users are urged to update to the latest firmware or patches to mitigate risks.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Memory Corruption

Weakness Enumeration

Related Identifiers

ASB-A-359692902
ASB-A-359699091
ASB-A-359699094
ASB-A-359699096
CVE-2024-20092
M-ALPS09028313

Affected Products

Mediatek