First published: Tue Mar 07 2023(Updated: )
In display drm, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07292593; Issue ID: ALPS07292593.
Credit: security@mediatek.com
Affected Software | Affected Version | How to fix |
---|---|---|
Android | =12.0 | |
Android | =13.0 | |
MediaTek MT6895 | ||
MediaTek MT6985T | ||
MediaTek MT8168 | ||
MediaTek MT8781 WiFi | ||
All of | ||
Any of | ||
Android | =12.0 | |
Android | =13.0 | |
Any of | ||
MediaTek MT6895 | ||
MediaTek MT6985T | ||
MediaTek MT8168 | ||
MediaTek MT8781 WiFi |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-20636 has a medium severity level due to a possible out of bounds write that could allow local escalation of privileges.
To fix CVE-2023-20636, users should apply the patch identified as ALPS07292593 provided by the vendor.
CVE-2023-20636 affects Android versions 12.0 and 13.0.
No, user interaction is not needed for the exploitation of CVE-2023-20636.
CVE-2023-20636 does not directly lead to remote code execution, but it can enable local escalation of privileges.