MediaTek MT9972
cpe:2.3:h:mediatek:mt9972:*:*:*:*:*:*:*
- ~12
- ~14
A vulnerability in the PlayReady Trusted Application (TA) component of MediaTek chipsets, specifically in the MT9972 chipset, has been identified. This issue arises from a missing bounds check, leading to a possible out-of-bounds read. Such a flaw could allow a malicious actor, who has already gained System privileges, to escalate privileges locally. The vulnerability does not require user interaction for exploitation. Affected software versions include Android 12.0 and 14.0.
Exploitation of this vulnerability could lead to unauthorized privilege escalation, allowing a user with System privileges to gain elevated rights or access.
MediaTek has issued a patch for this vulnerability, which can be applied by device manufacturers. Instructions for applying the patch are available through MediaTek's official channels.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.