CVE-2025-20645
Published: 03 March 2025
Description
In KeyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS09475476; Issue ID: MSV-2599.
Security Summary
CVE-2025-20645 is a vulnerability in the KeyInstall component that enables an out-of-bounds write due to a missing bounds check, classified under CWE-787. This issue affects MediaTek products, as documented in their March 2025 product security bulletin. The vulnerability was published on 2025-03-03 and carries a CVSS v3.1 base score of 7.8 (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H), indicating high impact potential from a local attack vector.
A malicious local actor who has already obtained System privilege can exploit this flaw to achieve further local escalation of privilege. Exploitation requires low attack complexity and no user interaction, allowing the attacker to potentially gain high confidentiality, integrity, and availability impacts through arbitrary code execution or system compromise.
MediaTek's advisory provides mitigation through Patch ID ALPS09475476 (Issue ID MSV-2599). Security practitioners should consult the full details at https://corp.mediatek.com/product-security-bulletin/March-2025 and apply the patch to vulnerable devices.
Details
- CWE(s)