Out-of-bounds write in MediaTek products - CVE-2024-20103
Published: October 8, 2024
Vulnerability identifier: #VU98115
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-20103
CWE-ID: CWE-787
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to improper input validation within wlan. A remote attacker can trick the victim to open a specially crafted file and execute arbitrary code.
Affected software
MT3605
MT6985
MT6989
MT6990
MT7927
MT8183
MT8512
MT8678
MT8695
MT8698
MT8796
MT8893
Google Android
MT6985
MT6989
MT6990
MT7927
MT8183
MT8512
MT8678
MT8695
MT8698
MT8796
MT8893
Google Android
How to mitigate CVE-2024-20103
Install security update from vendor's website.
Google Android - addressed in versions 12L 2024-10-05, 12 2024-10-05, 13 2024-10-05, 14 2024-10-05, 15 2024-10-05