VYPR
Unrated severityNVD Advisory· Published Jul 4, 2023· Updated Dec 4, 2024

CVE-2023-20754

CVE-2023-20754

Description

In keyinstall, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07563028; Issue ID: ALPS07588343.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Integer overflow in MediaTek keyinstall allows local privilege escalation via out-of-bounds write with System execution privileges.

Vulnerability

In the keyinstall component of MediaTek chipsets, an integer overflow (CWE-190) can lead to an out-of-bounds write. The vulnerability exists in multiple chipsets including MT6580, MT6731, MT6735, MT6737, MT6739, MT6753, MT6757, MT6757C, MT6757CD, MT6757CH, MT6761, MT6762, MT6763, MT6765, MT6768, MT6769, MT6771, MT6779, MT6781, MT6785, MT6789, MT6833, MT6835, and others [1]. Exploitation requires System execution privileges, and no user interaction is needed. The issue is identified by Patch ID ALPS07563028 and Issue ID ALPS07588343.

Exploitation

An attacker with System execution privileges can trigger the integer overflow in keyinstall, causing an out-of-bounds write. The exact sequence of operations is not publicly detailed, but the overflow occurs during key installation processing. No user interaction is required, and the attacker can execute the exploit locally on the device.

Impact

Successful exploitation leads to local escalation of privilege (EoP). Although the attacker already has System execution privileges, the out-of-bounds write can corrupt kernel memory or other critical structures, potentially allowing full compromise of the device or access to sensitive data [1].

Mitigation

MediaTek has provided patches to device OEMs as part of the July 2023 security bulletin [1]. The patch ID is ALPS07563028. OEMs are expected to incorporate the fix into their firmware updates. Users should apply updates from their device manufacturer when available. No workaround is documented, and the vulnerability is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog.

References
  1. July 2023

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • MediaTek, Inc./MT6580, MT6731, MT6735, MT6737, MT6739, MT6753, MT6757, MT6757C, MT6757CD, MT6757CH, MT6761, MT6762, MT6763, MT6765, MT6768, MT6769, MT6771, MT6779, MT6781, MT6785, MT6789, MT6833, MT6835, MT6853, MT6853T, MT6855, MT6873, MT6875, MT6877, MT6879, MT6883, MT6885, MT6886, MT6889, MT6891, MT6893, MT6895, MT6983, MT6985, MT8185, MT8321, MT8385, MT8666, MT8667, MT8765, MT8766, MT8768, MT8781, MT8786, MT8788, MT8789, MT8791, MT8791T, MT8797v5
    Range: Android 11.0, 12.0, 13.0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.