Impact
This vulnerability resides in the vdec component of MediaTek chipsets and results from a missing bounds check, permitting an out-of-bounds write. The flaw could let a local user elevate privileges without needing any additional execution privileges or user interaction. The impact is a compromise of device security at the system level, enabling the attacker to run code with higher privileges than originally granted.
Affected Systems
Vendors: MediaTek, Inc. Products: MediaTek chipsets. No specific affected version information is provided in the CVE data; all MediaTek chipset devices that include the vulnerable vdec implementation are potentially impacted.
Risk and Exploitability
The vulnerability allows local privilege escalation and can be triggered without user interaction. While no CVSS or EPSS score is available, the existence of an out-of-bounds write that promotes privilege elevation indicates a high severity scenario. The feature is exploitable by any user who can run code on the system and is not protected by additional access controls. Because it is a local issue, remote exploitation is not described, but once a user gains elevated privileges, they could achieve full device compromise. The CVE is not listed in CISA KEV, but the severity of the flaw warrants immediate attention.
OpenCVE Enrichment