VYPR
Unrated severityNVD Advisory· Published Jul 4, 2023· Updated Dec 4, 2024

CVE-2023-20756

CVE-2023-20756

Description

In keyinstall, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07510064; Issue ID: ALPS07549928.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Integer overflow in MediaTek keyinstall allows local privilege escalation via out-of-bounds write, requiring System execution privileges.

Vulnerability

In the keyinstall component of MediaTek chipsets, an integer overflow vulnerability (CWE-190) can lead to an out-of-bounds write. The affected chipsets include MT6580, MT6731, MT6735, MT6737, MT6739, MT6753, MT6757, MT6757C, MT6757CD, MT6757CH, MT6761, MT6762, MT6763, MT6765, MT6768, MT6769, MT6771, MT6779, MT6781, MT6785, MT6789, MT6833, MT6835, and others [1]. The vulnerability is present in the keyinstall functionality and requires System execution privileges to trigger.

Exploitation

An attacker with System execution privileges can exploit the integer overflow to cause an out-of-bounds write. No user interaction is required. The attacker would need to have local access to the device and the ability to execute code with System privileges. The exact sequence of steps is not detailed in the available references, but the integer overflow in keyinstall can be triggered to write beyond allocated memory boundaries.

Impact

Successful exploitation leads to local escalation of privilege (EoP) within the System context. The out-of-bounds write could allow the attacker to overwrite critical kernel or system data, potentially gaining elevated privileges or causing a denial of service. The impact is limited to the device's local environment.

Mitigation

MediaTek has released a patch (ALPS07510064) for this issue, which is included in the July 2023 security bulletin [1]. Device OEMs were notified at least two months prior to publication. Users should apply the latest firmware updates from their device manufacturer. No workaround is provided; updating to a patched version is the recommended mitigation.

References
  1. July 2023

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • MediaTek, Inc./MT6580, MT6731, MT6735, MT6737, MT6739, MT6753, MT6757, MT6757C, MT6757CD, MT6757CH, MT6761, MT6762, MT6763, MT6765, MT6768, MT6769, MT6771, MT6779, MT6781, MT6785, MT6789, MT6833, MT6835, MT6853, MT6853T, MT6855, MT6873, MT6875, MT6877, MT6879, MT6883, MT6885, MT6886, MT6889, MT6891, MT6893, MT6895, MT6983, MT6985, MT8185, MT8321, MT8385, MT8666, MT8667, MT8765, MT8766, MT8768, MT8781, MT8786, MT8788, MT8789, MT8791, MT8791T, MT8797v5
    Range: Android 12.0, 13.0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.