Heap-based Buffer Overflow in MediaTek products - CVE-2021-32487

 

Heap-based Buffer Overflow in MediaTek products - CVE-2021-32487

Published: March 7, 2023


Vulnerability identifier: #VU72935
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-32487
CWE-ID: CWE-122
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to a heap buffer overflow within Modem 2G RRM. A remote attacker can trick the victim to open a specially crafted file and execute arbitrary code.


Affected software

MT6768
MT6785T
MT6783
MT6771
MT6769Z
MT6769T
MT6769
MT6739
MT6767
MT6765T
MT6765
MT6763
MT6762M
MT6762D
MT6762
MT6761
MT6785
MT6779

How to mitigate CVE-2021-32487

Install security update from vendor's website.


External References

Related Security Bulletins