Impact
The vulnerability is a permissions bypass in the modem component of MediaTek chipsets, classified as CWE-280. An attacker who already has System privilege can execute code through the modem to elevate privileges, allowing local privilege escalation. The flaw does not require user interaction, so anyone with local access and System rights can exploit it, potentially compromising the entire device.
Affected Systems
MediaTek chipsets are affected. The issue resides in the modem component. No specific firmware or model versions were listed; the vulnerability applies to any firmware that includes the vulnerable modem code, until the patch ID MOLY01716533 is applied.
Risk and Exploitability
The CVSS score of 6.7 indicates medium severity, driven by local privilege escalation potential when a System privilege user can bypass permissions in the modem. The EPSS score of less than 1 % implies a low probability of exploitation at the time of this analysis, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires local code execution, which is feasible for an attacker with System-level access but not remotely or over the network. Thus, while the risk is moderate relative to ordinary privilege escalation flaws, the lack of user interaction means that once System privileges exist the flaw can be leveraged quickly.
OpenCVE Enrichment