#VU72934 Heap-based Buffer Overflow in MediaTek products - CVE-2021-32486
Published: March 7, 2023
Vulnerability identifier: #VU72934
Vulnerability risk: High
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2021-32486
CWE-ID: CWE-122
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerable software:
MT6739
MT6761
MT6762
MT6762D
MT6762M
MT6763
MT6765
MT6765T
MT6767
MT6768
MT6769
MT6769T
MT6769Z
MT6771
MT6783
MT6785T
MT6779
MT6785
MT6739
MT6761
MT6762
MT6762D
MT6762M
MT6763
MT6765
MT6765T
MT6767
MT6768
MT6769
MT6769T
MT6769Z
MT6771
MT6783
MT6785T
MT6779
MT6785
Software vendor:
MediaTek
MediaTek
Description
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a heap buffer overflow within Modem 2G RRM. A remote attacker can trick the victim to open a specially crafted file and execute arbitrary code.
Remediation
Install security update from vendor's website.