2025-03-13 19:03:49 +00:00

64 lines
2.1 KiB
JSON

{
"id": "CVE-2024-20056",
"sourceIdentifier": "security@mediatek.com",
"published": "2024-05-06T03:15:09.563",
"lastModified": "2025-03-13T18:15:36.880",
"vulnStatus": "Awaiting Analysis",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "In preloader, there is a possible escalation of privilege due to an insecure default value. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08528185; Issue ID: ALPS08528185."
},
{
"lang": "es",
"value": "En el preloader, existe una posible escalada de privilegios debido a un valor predeterminado inseguro. Esto podr\u00eda conducir a una escalada local de privilegios con permisos de ejecuci\u00f3n de System necesarios. La interacci\u00f3n del usuario no es necesaria para la explotaci\u00f3n. ID de parche: ALPS08528185; ID del problema: ALPS08528185."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
"baseScore": 6.7,
"baseSeverity": "MEDIUM",
"attackVector": "LOCAL",
"attackComplexity": "LOW",
"privilegesRequired": "HIGH",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "HIGH"
},
"exploitabilityScore": 0.8,
"impactScore": 5.9
}
]
},
"weaknesses": [
{
"source": "security@mediatek.com",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
}
],
"references": [
{
"url": "https://corp.mediatek.com/product-security-bulletin/May-2024",
"source": "security@mediatek.com"
},
{
"url": "https://corp.mediatek.com/product-security-bulletin/May-2024",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
]
}