Impact
An out‑of‑bounds write can occur in the display handling of MediaTek chipsets because a required bounds check is omitted from the code. The flaw permits a local attacker that already has System privilege to overwrite memory beyond the intended limits, thereby elevating privileges further. The exploitation does not require any user interaction once System access is obtained, and can be performed from any privileged user session.
Affected Systems
MediaTek chipset. No specific firmware versions are listed in the advisory, so the issue applies to all versions of the MediaTek chipset that expose the vulnerable display code.
Risk and Exploitability
The CVSS score is 6, and the EPSS score is lower than 1%, indicating a low to moderate probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires that an attacker first obtain System privilege; once achieved, the out‑of‑bounds write can elevate their privileges, potentially compromising confidentiality, integrity, or availability of the system. Because the flaw is local and requires no remote interaction, the primary risk is to privileged users already on the device. Patch ID ALPS11009963 addresses the flaw.
OpenCVE Enrichment