MediaTek MT6899
cpe:2.3:h:mediatek:mt6899:*:*:*:*:*:*:*, +1 more
- >= MT6899, < MT6899-D81
A use-after-free vulnerability has been identified in the Digital Post-Processing Engine (DPE) of certain MediaTek chipsets. This vulnerability can lead to memory corruption, potentially allowing a malicious actor with System privileges to escalate privileges further. The issue arises from improper memory management, where memory is freed but still accessible, creating a risk of exploitation. Notably, user interaction is not required for this vulnerability to be exploited.
Exploitation of this vulnerability could result in unauthorized privilege escalation, allowing a user with System privileges to gain elevated rights or access.
Device OEMs have been notified of this vulnerability and the corresponding security patches are available. For further information, OEMs can contact their MediaTek representative.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.