Impact
A heap buffer overflow exists in the MediaTek Telephony component, which can corrupt heap memory. The flaw, identified as CWE‑122, enables a local attacker who already holds system privileges to potentially elevate privileges further, thereby compromising device security if exploited successfully.
Affected Systems
Any device that incorporates a MediaTek chipset with Telephony support is affected. The advisory does not specify firmware or OS versions, so all releases using the Telephony subsystem remain vulnerable until the vendor releases patch ALPS11006447 (MSV‑7871).
Risk and Exploitability
The CVSS score of 6.7 indicates moderate severity, while the EPSS score is below 1% and the vulnerability is not listed in CISA KEV. Exploitation does not require user interaction; an attacker with local system privileges can trigger the overflow by interacting with the Telephony subsystem to achieve further privilege escalation. Because the local system privilege is a prerequisite, the risk is confined to compromised local users.
OpenCVE Enrichment