CVE-2023-20718: Input Validation
In vcu, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07645181; Issue ID: ALPS07645181.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-20718?
CVE-2023-20718 is a vulnerability in vcu that allows for a possible out of bounds write due to a missing bounds check.
What is the severity of CVE-2023-20718?
The severity of CVE-2023-20718 is medium with a severity value of 6.7.
How can CVE-2023-20718 be exploited?
CVE-2023-20718 can be exploited without user interaction, leading to local escalation of privilege requiring system execution privileges.
Which software versions are affected by CVE-2023-20718?
Google Android versions 11.0, 12.0, and 13.0, as well as Yocto Project version 4.0 are affected by CVE-2023-20718.
Is MediaTek MT6768 vulnerable to CVE-2023-20718?
No, MediaTek MT6768 is not vulnerable to CVE-2023-20718.