CVE-2024-20121

CVE-2024-20121

Vendor Mediatek, Inc.
Product MT6765, MT6768, MT6833, MT6835, MT6853, MT6855, MT6879, MT6886, MT6893, MT6983, MT6989, MT8321, MT8385, MT8765, MT8766, MT8768, MT8771, MT8775, MT8781, MT8786, MT8788, MT8789, MT8791T, MT8792, MT8795T, MT8796, MT8797, MT8798
Weakness CWE-787
Published November 4, 2024
Last update November 4, 2024

CVSS base score

What the vulnerability does

01Description

In KeyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08956986; Issue ID: MSV-1574.

Key dates

02Disclosure timeline

November 4, 2024 CVE published
November 4, 2024 Record updated