CVE-2018-9371

CVSS 3.1 Score 6.4 of 10 (medium)

Details

Published Nov 19, 2024
Updated: Nov 22, 2024
CWE ID 125
CWE ID 787

Summary

CVE-2018-9371 is a vulnerability affecting the Mediatek Preloader. This issue stems from an exposed interface that permits arbitrary peripheral memory mapping, with insufficient blacklisting or whitelisting. Consequently, attackers can perform out-of-bounds reads and writes, potentially leading to local elevation of privilege. Physical access to the device is required, and user interaction is necessary for successful exploitation.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share