CVE-2024-20072: Input Validation
In wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00364732; Issue ID: MSV-1332.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-20072?
CVE-2024-20072 has a high severity rating due to its potential for local escalation of privilege.
How do I fix CVE-2024-20072?
To mitigate CVE-2024-20072, apply the patch ID WCNCR00364732 as soon as it is available.
Which software versions are affected by CVE-2024-20072?
CVE-2024-20072 affects versions of Mediatek Software Development Kit up to 5.0.5.0 and certain versions of OpenWrt including 19.07.0, 21.02.0, and 23.05.
Is user interaction required to exploit CVE-2024-20072?
No, user interaction is not needed to exploit CVE-2024-20072.
What could happen if CVE-2024-20072 is exploited?
If CVE-2024-20072 is exploited, it could lead to an out-of-bounds write resulting in local escalation of privileges.