Out-of-bounds write in MediaTek products - CVE-2024-20011
Published: February 6, 2024
Vulnerability identifier: #VU86133
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-20011
CWE-ID: CWE-787
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to an incorrect bounds check within alac decoder. A remote attacker can trick the victim to open a specially crafted file and execute arbitrary code.
Affected software
MT8176
MT8312D
MT8312C
MT8195Z
MT8195
MT8188T
MT8188
MT8185
MT8183
MT6985
MT8175
MT8173
MT8168
MT8167S
MT8167
MT8135
MT8127
Google Android
MT8312D
MT8312C
MT8195Z
MT8195
MT8188T
MT8188
MT8185
MT8183
MT6985
MT8175
MT8173
MT8168
MT8167S
MT8167
MT8135
MT8127
Google Android
How to mitigate CVE-2024-20011
Install security update from vendor's website.
Google Android - addressed in versions 11 2024-02-05, 12L 2024-02-05, 12 2024-02-05, 13 2024-02-05, 14 2024-02-05