CVE-2018-9371

CVSS 3.1 Score 6.4 of 10 (medium)

Details

Published Nov 19, 2024
Updated: Nov 22, 2024
CWE ID 125
CWE ID 787

Summary

CVE-2018-9371 is a vulnerability affecting the Mediatek Preloader. The issue stems from an exposed interface that permits arbitrary peripheral memory mapping with insufficient restrictions. This results in out-of-bounds reads and writes, which can be exploited to gain local elevation of privilege. However, it is important to note that physical access to the device is required for exploitation, and no additional execution privileges are necessary. This vulnerability poses a significant risk, as attackers can potentially gain higher system access with minimal requirements.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share