Impact
The vulnerability is a permissions bypass in the modem component of MediaTek chipsets, classified as CWE-280. An attacker who already has System privilege can execute code through the modem to elevate privileges, allowing local privilege escalation. The flaw does not require user interaction, so anyone with local access and System rights can exploit it, potentially compromising the entire device.
Affected Systems
MediaTek chipsets are affected. The issue resides in the modem component. No specific firmware or model versions were listed; the vulnerability applies to any firmware that includes the vulnerable modem code, until the patch ID MOLY01716533 score of 6.7 indicates medium severity, driven by local privilege escalation potential when a System privilege user can bypass permissions in the modem.
Risk and Exploitability
The CVSS score of 6.7 classifies this flaw as medium severity, indicating modest but non-negligible risk. The EPSS score of less than 1 % suggests a low likelihood of exploitation at present, and the vulnerability is not currently listed in CISA KEV catalog. Because the already possess System privileges and local code execution, exploitation is limited to devices with full system access; remote exploitation is not supported. Nevertheless, once System privileges exist, the permissions bypass can be used to elevate privileges quickly, potentially compromising all components of the affected MediaTek modem.
OpenCVE Enrichment