Impact
An out‑of‑bounds write in the Power HAL module of MediaTek chipsets occurs because a bounds check is omitted. This flaw, classified as CWE-121, could allow a locally running entity that already has System privilege to overwrite memory beyond its intended bounds, potentially corrupting critical data structures or code paths. The result is an escalation of privileges from System level to higher or equivalent authority within the device. User interaction is not required for exploitation.
Affected Systems
MediaTek, Inc. chipsets are affected. The vulnerability exists in the Power HAL component of these hardware platforms. No specific affected firmware or hardware versions are disclosed.
Risk and Exploitability
The CVSS score is 6.7, the EPSS score is less than 1%, and the issue is not listed in the CISA KEV catalog. The flaw can be triggered locally by any process running with System permissions. Attackers with such access could manipulate memory without needing to interact with a user interface. The potential impact, if exploited successfully, would be severe due to the high privilege level involved.
OpenCVE Enrichment