Cyber Posture

CVE-2025-20645

High

Published: 03 March 2025

Published
03 March 2025
Modified
22 April 2025
KEV Added
Patch
CVSS Score 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.0005 14.7th percentile
Risk Priority 16 60% EPSS · 20% KEV · 20% CVSS

Description

In KeyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS09475476; Issue ID: MSV-2599.

Security Summary

CVE-2025-20645 is a vulnerability in the KeyInstall component that enables an out-of-bounds write due to a missing bounds check, classified under CWE-787. This issue affects MediaTek products, as documented in their March 2025 product security bulletin. The vulnerability was published on 2025-03-03 and carries a CVSS v3.1 base score of 7.8 (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H), indicating high impact potential from a local attack vector.

A malicious local actor who has already obtained System privilege can exploit this flaw to achieve further local escalation of privilege. Exploitation requires low attack complexity and no user interaction, allowing the attacker to potentially gain high confidentiality, integrity, and availability impacts through arbitrary code execution or system compromise.

MediaTek's advisory provides mitigation through Patch ID ALPS09475476 (Issue ID MSV-2599). Security practitioners should consult the full details at https://corp.mediatek.com/product-security-bulletin/March-2025 and apply the patch to vulnerable devices.

Details

CWE(s)
CWE-787

Affected Products

google
android
14.0, 15.0

References