Impact
A heap buffer overflow exists in the MediaTek Telephony component, allowing an attacker to corrupt memory on the heap. This flaw is classified as CWE‑122 and can lead to local privilege escalation. If exploited successfully, an adversary who already operates with system privileges can leverage the overflow to achieve higher privileges or to compromise the security of the device.
Affected Systems
Devices that incorporate MediaTek chipset Telephony assemblies are affected. No exact firmware or operating system versions are specified in the advisory, so any release employing the Telephony subsystem could be vulnerable until the vendor patch is deployed.
Risk and Exploitability
The CVSS score of 6.7 indicates moderate severity, while the EPSS score is below 1% and the vulnerability is not listed in the CISA KEV catalog. Based on the local system-level access to trigger the overflow; no user interaction is required. If successful, the attacker can elevate privileges locally. The patch ID ALPS11006447 (Issue ID MSV-7871) addresses this issue.
OpenCVE Enrichment