CVE-2024-20018: Input Validation
Published Mar 4, 2024
·Updated
In wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00348479; Issue ID: MSV-1019.
Affected Software
2 affected components
All of the following
MediaTek Software Development Kit<=5.1.0.0
MediaTek MT7615
Event History
Mar 4, 2024
CVE Published
via MITRE·02:43 AM
Data Sourced
via MITRE·02:43 AM
DescriptionWeakness
Data Sourced
via NVD·03:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-20018?
The severity of CVE-2024-20018 is classified as high due to the potential for local escalation of privilege.
2
How do I fix CVE-2024-20018?
To fix CVE-2024-20018, apply the patch identified by Patch ID WCNCR00348479.
3
What software is affected by CVE-2024-20018?
CVE-2024-20018 affects the MediaTek Linkit Software Development Kit versions up to 5.1.0.0.
4
Can CVE-2024-20018 be exploited without user interaction?
Yes, CVE-2024-20018 can be exploited without any user interaction.
5
What type of vulnerability is CVE-2024-20018?
CVE-2024-20018 is identified as an out of bounds write vulnerability due to improper input validation.