CVE-2024-20125: Medium severity android vulnerability
In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained System privileges. User interaction is not needed for exploitation. Patch ID: ALPS09046782; Issue ID: MSV-1728.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-20125?
CVE-2024-20125 is considered a high severity vulnerability due to the potential for local escalation of privilege.
How do I fix CVE-2024-20125?
To fix CVE-2024-20125, apply the patch identified by ALPS09046782 provided in the security bulletin.
Who is affected by CVE-2024-20125?
CVE-2024-20125 affects devices running Google Android that utilize the vdec component.
Can CVE-2024-20125 be exploited remotely?
No, exploitation of CVE-2024-20125 requires that the attacker has already obtained System privileges locally.
Does CVE-2024-20125 require user interaction for exploitation?
No, CVE-2024-20125 does not require user interaction for exploitation.