Impact
The vulnerability is a race condition in the display subsystem of MediaTek chipset software, which can allow a local attacker who already possesses System level privileges to execute code with higher privileges. This flaw is categorized as CWE-367. The likely attack vector is exploiting concurrent display operations, as inferred from the description that the flaw can be triggered by mismanagement of such operations. Based on the statement that no user interaction is required, it is inferred that the attacker does not need to engage the user for exploitation.
Affected Systems
Affected systems include MediaTek, Inc. MediaTek chipset devices. No specific version information is provided in the advisory.
Risk and Exploitability
The EPSS score <1% and the vulnerability not being listed in the CISA KEV catalog suggest that exploitation likelihood is low at present. However, because the flaw requires that an attacker already have System privileges to trigger the race condition, it is inferred that prior compromise is necessary for exploitation. Once that condition is met, local privilege escalation can occur without further user interaction. Despite the absence of a remote exploitation path, the potential impact remains high if an attacker already controls the device. The CVSS score of 6 indicates a medium severity, recommending timely patching.
OpenCVE Enrichment