CVE-2023-20745
6.7
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 0.8 / Impact: 5.9
Source: NVD
Description
In vcu, there is a possible out of bounds write due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07519142; Issue ID: ALPS07560694.
Affected (4)
Products: Google: Android · Linuxfoundation: Iot Yocto, Yocto
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 12.0 | |
| Version 22.2 | |
| Version 4.0 |
| Running on/with | Platform Versions |
|---|---|
Mediatek Mt6789 | All versions |
Mediatek Mt6855 | All versions |
Mediatek Mt8185 | All versions |
Mediatek Mt8195 | All versions |
Mediatek Mt8365 | All versions |
Mediatek Mt8395 | All versions |
Mediatek Mt8781 | All versions |
Mediatek Mt8786 | All versions |
Mediatek Mt8789 | All versions |
Mediatek Mt8791 | All versions |
Mediatek Mt8797 | All versions |
References (2)
Source: security@mediatek.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.