CVE-2024-20131

MEDIUM EPSS 7.3%
Published Dec 2, 20241y ago · Modified Jun 17, 20261w ago
6.7 CVSS 3.1
Medium
Find Similar
Published Dec 2, 2024 1y ago
Last Modified Jun 17, 2026 1w ago

Description

In Modem, there is a possible escalation of privilege due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01395886; Issue ID: MSV-1873.

CVSS Details

Base Score
6.7
Exploitability
0.8
Impact
5.9
Vector string
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Vector Local
Attack Complexity Low
Privileges Required High
User Interaction None
Scope Unchanged
Confidentiality High
Integrity High
Availability High

Threat Intelligence

EPSS Exploit Probability
7.3% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available

Weaknesses 1

CWE-787 Out-of-bounds Write Memory Safety

Affected Products 33

VendorProductVersionRange
mediateknr16*any
mediateknr17*any
mediatekmt2737*any
mediatekmt2739*any
mediatekmt6789*any
mediatekmt6813*any
mediatekmt6815*any
mediatekmt6835*any
mediatekmt6835t*any
mediatekmt6855*any
mediatekmt6878*any
mediatekmt6878t*any
mediatekmt6879*any
mediatekmt6886*any
mediatekmt6895*any
mediatekmt6895t*any
mediatekmt6896*any
mediatekmt6897*any
mediatekmt6899*any
mediatekmt6980*any
mediatekmt6980d*any
mediatekmt6983*any
mediatekmt6985*any
mediatekmt6986*any
mediatekmt6986d*any
mediatekmt6988*any
mediatekmt6989*any
mediatekmt6990*any
mediatekmt6991*any
mediatekmt8673*any
mediatekmt8676*any
mediatekmt8795t*any
mediatekmt8798*any

References 1

  • corp.mediatek.com https://corp.mediatek.com/product-security-bulletin/December-2024
    Vendor Advisory

Remediation

No remediation data recorded yet

Check vendor advisories and the NVD entry for patch availability.