CVE-2026-20533: Integer Overflow
In display, there is a possible escalation of privilege due to an integer overflow. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11296678; Issue ID: MSV-9167.
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch ALPS11296678
Event History
Frequently Asked Questions
What level of access does an attacker need before exploiting this issue?
The attacker must already have System privilege. The issue could then be used for further local escalation of privilege.
Does exploitation require user interaction or remote access?
No user interaction is required. The described impact is local escalation of privilege; the available information does not describe remote exploitation.
How can I identify the relevant vendor remediation?
The vendor identifies the fix as Patch ID ALPS11296678 and tracks the issue as MSV-9167.