PT-2024-8963 · Mediatek · Mediatek Vdec

Published

2024-12-02

·

Updated

2025-04-22

·

CVE-2024-20125

CVSS v2.0

6.8

Medium

VectorAV:L/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: MediaTek vdec (affected versions not specified)
Description: The issue is related to a missing bounds check in the vdec component of MediaTek microprogram software, which could lead to an out of bounds write. This could result in local escalation of privilege if a malicious actor has already obtained System privileges. User interaction is not needed for exploitation.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Memory Corruption

Weakness Enumeration

Related Identifiers

ASB-A-371710871
BDU:2024-10644
CVE-2024-20125
M-ALPS09046782

Affected Products

Mediatek Vdec