Memory corruption in MediaTek products - CVE-2024-20082

 

Memory corruption in MediaTek products - CVE-2024-20082

Published: August 5, 2024


Vulnerability identifier: #VU95375
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-20082
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to a missing bounds check within Modem. A remote attacker can trick the victim to open a specially crafted file and execute arbitrary code.


Affected software

MT6886
MT6990
MT6989
MT6985
MT6983
MT6980D
MT6980
MT6897
MT6896
MT6895T
MT6895
MT6890
MT2735
MT6880
MT6879
MT6875T
MT6855
MT6835T
MT6835
MT6833
MT2737
MT6893
MT6891
MT6889
MT6885
MT6883
MT6877
MT6875
MT6873
MT6853
Google Android

How to mitigate CVE-2024-20082

Install security update from vendor's website.

Google Android - addressed in versions 12L 2024-08-05, 12 2024-08-05, 13 2024-08-05, 14 2024-08-05

External References

Related Security Bulletins