CVE-2025-20672
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)
Description
In Bluetooth driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00412257; Issue ID: MSV-3292.
Affected (5)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.6 |
| Running on/with | Platform Versions |
|---|---|
Mediatek Mt7902 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.6 |
| Running on/with | Platform Versions |
|---|---|
Mediatek Mt7921 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.6 |
| Running on/with | Platform Versions |
|---|---|
Mediatek Mt7922 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.6 |
| Running on/with | Platform Versions |
|---|---|
Mediatek Mt7925 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.6 |
| Running on/with | Platform Versions |
|---|---|
Mediatek Mt7927 | All versions |
References (1)
Source: security@mediatek.com
Vendor Advisory
Timeline
No history available yet.