CVE-2024-20115: Medium severity android vulnerability
Published Nov 4, 2024
·Updated
In ccu, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09036695; Issue ID: MSV-1713.
Affected Software
12 affected components
All of the following
Any of the following
Google Android=12.0
Google Android=13.0
Google Android=14.0
Google Android=15.0
Any of the following
MediaTek Mt6833
MediaTek Mt6853
MediaTek Mt6873
MediaTek Mt6877
MediaTek Mt6885
MediaTek Mt6893
MediaTek Mt8188
MediaTek Mt8195
Event History
Nov 4, 2024
CVE Published
via MITRE·01:49 AM
Data Sourced
via MITRE·01:49 AM
DescriptionWeakness
Data Sourced
via NVD·02:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-20115?
CVE-2024-20115 has a high severity due to the potential for local escalation of privilege.
2
How do I fix CVE-2024-20115?
To fix CVE-2024-20115, apply the patch identified as ALPS09036695.
3
Who can exploit CVE-2024-20115?
CVE-2024-20115 can be exploited without user interaction, making it particularly dangerous.
4
What are the affected versions for CVE-2024-20115?
CVE-2024-20115 affects Android versions 12.0, 13.0, 14.0, and 15.0.
5
What could be the impact of CVE-2024-20115?
The impact of CVE-2024-20115 is a local escalation of privilege, allowing unauthorized actions with system execution privileges.