Impact
In the MediaTek apusys component, a bounds check is missing, allowing a local attacker who already possesses system privileges to manipulate memory. This omission can lead to a full privilege escalation, granting the attacker complete control over the device. The weakness is classified as a Bounds Checking error (CWE-749).
Affected Systems
MediaTek, Inc. MediaTek chipset. The vulnerability is documented for devices using the apusys component and can be mitigated with firmware patch AUTO00837766, Issue ID MSV-6767. No specific version range is supplied in the advisory.
Risk and Exploitability
Exploitation requires the attacker to have local system privileges; no user interaction is needed. Because the EPSS score is <1% and the CVSS score of 6 indicates moderate severity, and the issue is not listed in the CISA KEV catalog, the overall exposure is considered moderate. An attacker with system access could overwrite critical kernel data structures via the missing bounds check, elevating their privileges to full device control.
OpenCVE Enrichment