#VU86133 Out-of-bounds write in MediaTek products - CVE-2024-20011
Published: February 6, 2024
Vulnerability identifier: #VU86133
Vulnerability risk: High
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2024-20011
CWE-ID: CWE-787
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerable software:
MT6985
MT8127
MT8135
MT8167
MT8167S
MT8168
MT8173
MT8175
MT8176
MT8183
MT8185
MT8188
MT8188T
MT8195
MT8195Z
MT8312C
MT8312D
MT6985
MT8127
MT8135
MT8167
MT8167S
MT8168
MT8173
MT8175
MT8176
MT8183
MT8185
MT8188
MT8188T
MT8195
MT8195Z
MT8312C
MT8312D
Software vendor:
MediaTek
MediaTek
Description
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to an incorrect bounds check within alac decoder. A remote attacker can trick the victim to open a specially crafted file and execute arbitrary code.
Remediation
Install security update from vendor's website.