Impact
This vulnerability resides in the vdec component of MediaTek chipsets and results from a missing bounds check, permitting an out‑of‑bounds write. The flaw could let a local user elevate privileges without needing any additional execution privileges or user interaction. The impact is a compromise of device security at the system level, enabling the attacker to run code with higher privileges than originally granted.
Affected Systems
The affected systems are MediaTek, Inc. MediaTek chipset devices. No specific affected version information is provided in the CVE data; all MediaTek chipset devices that include the vulnerable vdec implementation are potentially impacted.
Risk and Exploitability
The vulnerability allows local privilege escalation and can be triggered without user interaction. A CVSS score of 8.4 indicates a high severity. Because no EPSS score is available, the likelihood of exploitation cannot be quantified, but the flaw is likely to be targeted due to its privilege escalation nature. The feature is exploitable by any user who can run code on the system and is not protected by additional access controls. Because it is a local issue, remote exploitation is not described, but once a user gains elevated privileges, they could achieve full device compromise. The CVE is not listed in CISA KEV, but the severity of the flaw warrants immediate attention.
OpenCVE Enrichment