CVE-2024-20021

In atf spm, there is a possible way to remap physical memory to virtual memory due to a logic error. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08584568; Issue ID: MSV-1249.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:*
OR cpe:2.3:h:mediatek:mt6768:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6781:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6785:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6833:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6853:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6873:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6877:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6885:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6893:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8168:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8183:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8188:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8188t:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8195:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8195z:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8321:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8362a:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8365:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8385:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8666:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8666a:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8666b:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8667:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8673:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8675:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8676:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8678:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8765:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8766:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8766z:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8768:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8768a:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8768b:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8768t:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8768z:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8781:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8786:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8788:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8788t:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8788x:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8788z:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8792:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8795t:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8796:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8798:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-05-06 03:15

Updated : 2025-04-30 16:42


NVD link : CVE-2024-20021

Mitre link : CVE-2024-20021

CVE.ORG link : CVE-2024-20021


JSON object : View

Products Affected

mediatek

  • mt8766z
  • mt8781
  • mt8795t
  • mt8676
  • mt8195
  • mt6833
  • mt6885
  • mt8673
  • mt8768
  • mt8667
  • mt8321
  • mt8666b
  • mt6785
  • mt6768
  • mt6893
  • mt8365
  • mt8798
  • mt8188t
  • mt8786
  • mt6853
  • mt8385
  • mt8188
  • mt8768a
  • mt8183
  • mt8792
  • mt8788z
  • mt8362a
  • mt8768b
  • mt8666
  • mt8195z
  • mt8766
  • mt8768z
  • mt8765
  • mt8168
  • mt8675
  • mt6873
  • mt8678
  • mt6877
  • mt8768t
  • mt8788
  • mt8666a
  • mt6781
  • mt8788t
  • mt8788x
  • mt8796

google

  • android
CWE
CWE-269

Improper Privilege Management

NVD-CWE-noinfo