Several vulnerabilities affecting MediaTek processors have been identified, potentially allowing attackers to escalate privileges on affected devices.
These vulnerabilities span multiple components, including video decoding, telephony, power management, and modem functionalities, posing significant risks to users worldwide.
The vulnerabilities, identified by their Common Vulnerabilities and Exposures (CVEs), highlight issues primarily related to out-of-bounds reads and writes, stack overflow, and uncaught exceptions, as a report by Mediatek.
Such flaws can lead to various security threats, including local escalation of privilege and denial of service attacks, with minimal user interaction required for exploitation.
Leveraging 2024 MITRE ATT&CK Results for SME & MSP Cybersecurity Leaders – Attend Free Webinar
Table of CVEs and Details
The following table details all identified CVEs and their severity levels, vulnerability types, affected chipsets, and software versions.
CVE ID | Title | Severity | CWE ID | Affected Software Versions |
CVE-2024-20125 | Out-of-bounds write in vdec | High | CWE-787 | Android 13.0, 14.0 |
CVE-2024-20129 | Out-of-bounds read in Telephony | Medium | CWE-125 | Android 13.0, 14.0, 15.0 |
CVE-2024-20128 | Out-of-bounds read in Telephony | Medium | CWE-125 | Android 13.0, 14.0, 15.0 |
CVE-2024-20127 | Out-of-bounds read in Telephony | Medium | CWE-125 | Android 13.0, 14.0, 15.0 |
CVE-2024-20130 | Stack overflow in power | Medium | CWE-121 | Android 14.0, 15.0 |
CVE-2024-20131 | Out-of-bounds write in Modem | Medium | CWE-787 | Modem NR16 |
CVE-2024-20132 | Out-of-bounds write in Modem | Medium | CWE-787 | Modem NR16 partial branches |
CVE-2024-20133 | Out-of-bounds write in Modem | Medium | CWE-787 | Modem NR16 |
CVE-2024-20134 | Out-of-bounds write in ril | Medium | CWE-787 | Android 14.0, 15.0 |
CVE-2024-20135 | Out-of-bounds write in soundtrigger | Medium | CWE-787 | Android 15.0 |
CVE-2024-20136 | Out-of-bounds read in DA | Medium | CWE-125 | Android 12.0, 13.0, 14.0, 15.0, openWRT 19.07, RDK-B |
CVE-2024-20137 | Uncaught exception in wlan | Medium | CWE-248 | SDK release 7.4.0.1, 7.6.7.2 and before |
CVE-2024-20116 | Out-of-bounds read in cmdq | Medium | CWE-125 | Android 12.0 |
CVE-2024-20138 | Out-of-bounds read in wlan | Medium | CWE-125 | SDK release 3.3 and before |
CVE-2024-20139 | Reachable assertion in Bluetooth | Medium | CWE-617 | Android 13.0, 14.0, openWRT 23.05 |
These vulnerabilities pose several significant risks:
To safeguard against these vulnerabilities, it is crucial to take the following steps:
The discovery of these vulnerabilities underscores the ongoing challenges in maintaining security within complex hardware and software ecosystems like those involving MediaTek processors.
Comprehensive and timely responses are essential to mitigate the risks posed and protect users from potential exploitation.
Analyse Advanced Malware & Phishing Analysis With ANY.RUN Black Friday Deals : Get up to 3 Free Licenses.
Recent research uncovered a novel crypto-jacking attack targeting the Python Package Index (PyPI), where malicious…
Amazon has taken a significant step forward to enhance the security of its cloud environment.…
In a recent announcement, Linus Torvalds, the creator of Linux, officially released the first release…
Cybersecurity researchers have identified a critical 0-day vulnerability in Windows Server 2012 and Server 2012…
A critical vulnerability identified as CVE-2024-44308 has been actively exploited in the wild, affecting multiple…
Researchers uncovered the resurgence of APT-C-01, also known as the Poison Ivy group, an advanced…