Out-of-bounds write in MediaTek products - CVE-2024-20100

 

Out-of-bounds write in MediaTek products - CVE-2024-20100

Published: October 8, 2024


Vulnerability identifier: #VU98113
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-20100
CWE-ID: CWE-787
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to improper input validation within wlan. A remote attacker can trick the victim to open a specially crafted file and execute arbitrary code.


Affected software

MT3605
MT6985
MT6989
MT6990
MT7927
MT8183
MT8365
MT8512
MT8676
MT8678
MT8695
MT8698
MT8755
MT8775
MT8792
MT8796
Google Android

How to mitigate CVE-2024-20100

Install security update from vendor's website.

Google Android - addressed in versions 12L 2024-10-05, 12 2024-10-05, 13 2024-10-05, 14 2024-10-05, 15 2024-10-05

External References

Related Security Bulletins