VYPR
Unrated severityNVD Advisory· Published Dec 17, 2021· Updated Aug 3, 2024

CVE-2021-0679

CVE-2021-0679

Description

In apusys, there is a possible memory corruption due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05672107; Issue ID: ALPS05687781.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

In apusys, a missing bounds check can cause memory corruption, leading to local escalation of privilege with System execution privileges.

Vulnerability

In the apusys driver of MediaTek chipsets, a missing bounds check can lead to memory corruption. The vulnerability affects devices using affected chipsets (including MT6570, MT6580, MT6735, MT6737, MT6739, MT6750, MT6750S, MT6753, MT6755, MT6755S, MT6757, MT6757C, MT6757CD, MT6757CH, MT6758, MT6761, MT6763, MT6765, MT6768, MT6771, MT6779, MT6781, MT6785, MT6797, MT6799, MT6833, and others) as per the October 2021 security bulletin [1]. The vulnerability is classified as CVE-2021-0679 with a Medium severity [1].

Exploitation

An attacker requires System execution privileges to trigger the vulnerability. User interaction is not needed [1]. The exact exploitation steps are not detailed in the public reference, but the missing bounds check in the apusys memory subsystem can be leveraged to corrupt memory [1].

Impact

Successful exploitation could lead to memory corruption, potentially enabling local escalation of privilege within the kernel context [1]. The attacker can gain elevated privileges on the targeted device.

Mitigation

MediaTek has released a security patch (Patch ID: ALPS05672107) for this issue [1]. Device OEMs have been notified and are expected to deploy the fix. Users should apply security updates from their device manufacturer when available. The patch is included in the December 2021 MediaTek security bulletin [1].

References
  1. December 2021

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.