CVE-2023-20655 | MediaTek MT8891 mmsdk privileges management (ALPS07203022 / EUVD-2023-24834)
A vulnerability, which was classified as problematic, has been found in MediaTek MT2715, MT6580, MT6735, MT6737, MT6739, MT6753, MT6761, MT6765, MT6768, MT6771, MT6779, MT6781, MT6785, MT6789, MT6833, MT6853, MT6853T, MT6855, MT6873, MT6877, MT6879, MT6883, MT6885, MT6889, MT6893, MT6895, MT6983, MT8167, MT8167S, MT8168, MT8173, MT8175, MT8185, MT8192, MT8195, MT8321, MT8362A, MT8365, MT8385, MT8395, MT8666, MT8667, MT8673, MT8675, MT8765, MT8766, MT8768, MT8771, MT8781, MT8786, MT8788, MT8789, MT8791, MT8791T, MT8795T, MT8797, MT8798, MT8871 and MT8891. This affects an unknown part of the component mmsdk. This manipulation causes improper privilege management.
This vulnerability is registered as CVE-2023-20655. The attack needs to be launched locally. No exploit is available.
Applying a patch is the recommended action to fix this issue.