VulnerabilityAnalyzed
CVE-2024-20017
In wlan service, there is a possible out of bounds write due to improper input validation.
CRITICAL 9.8EPSS 46.6%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 46.6%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation Patch ID: WCNCR00350938; Issue ID: MSV-1132.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 46.61% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20, CWE-787
- Affected
- mediatek/software development kit · openwrt/openwrt
- Source
- security@mediatek.com
References
- https://corp.mediatek.com/product-security-bulletin/March-2024Vendor Advisory
- https://blog.coffinsec.com/0day/2024/08/30/exploiting-CVE-2024-20017-four-different-ways.htmlExploit, Technical Description, Third Party Advisory
- https://blog.sonicwall.com/en-us/2024/09/critical-exploit-in-mediatek-wi-fi-chipsets-zero-click-vulnerability-cve-2024-20017-threatens-routers-and-smartphones/Exploit, Third Party Advisory
- https://corp.mediatek.com/product-security-bulletin/March-2024Vendor Advisory
- https://news.ycombinator.com/item?id=41605680Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.