Impact
The vulnerability is an out-of-bounds write caused by a heap buffer overflow in the vdec component of MediaTek chipsets. This flaw permits a local attacker to overwrite arbitrary memory locations without requiring any execution privileges or user interaction. Such an overwrite can allow the attacker to elevate privileges on the system, potentially granting them full control over the device.
Affected Systems
MediaTek chipsets are affected. The specific affected versions are not listed in the available data. A patch identified by ALPS11262030 addresses the issue and should be applied as soon as possible.
Risk and Exploitability
The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, indicating no publicly documented exploits as of now. However, because the flaw can be triggered locally without user interaction and can lead to privilege escalation, the risk is significant. The attack vector is likely a local process or user with access to the vulnerable component. Prompt application of the vendor‑supplied patch is strongly recommended to mitigate this risk.
OpenCVE Enrichment