CVE-2024-20021
MEDIUMDescription
In atf spm, there is a possible way to remap physical memory to virtual memory due to a logic error. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08584568; Issue ID: MSV-1249.
Is your site exposed to CVE-2024-20021?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| android | |
| android | |
| android | |
| mediatek | mt6768 |
| mediatek | mt6781 |
| mediatek | mt6785 |
| mediatek | mt6833 |
| mediatek | mt6853 |
| mediatek | mt6873 |
| mediatek | mt6877 |
| mediatek | mt6885 |
| mediatek | mt6893 |
| mediatek | mt8168 |
| mediatek | mt8183 |
| mediatek | mt8188 |
| mediatek | mt8188t |
| mediatek | mt8195 |
| mediatek | mt8195z |
| mediatek | mt8321 |
| mediatek | mt8362a |
| mediatek | mt8365 |
| mediatek | mt8385 |
| mediatek | mt8666 |
| mediatek | mt8666a |
| mediatek | mt8666b |
| mediatek | mt8667 |
| mediatek | mt8673 |
| mediatek | mt8675 |
| mediatek | mt8676 |
| mediatek | mt8678 |
| mediatek | mt8765 |
| mediatek | mt8766 |
| mediatek | mt8766z |
| mediatek | mt8768 |
| mediatek | mt8768a |
| mediatek | mt8768b |
| mediatek | mt8768t |
| mediatek | mt8768z |
| mediatek | mt8781 |
| mediatek | mt8786 |
| mediatek | mt8788 |
| mediatek | mt8788t |
| mediatek | mt8788x |
| mediatek | mt8788z |
| mediatek | mt8792 |
| mediatek | mt8795t |
| mediatek | mt8796 |
| mediatek | mt8798 |
References
Frequently Asked Questions
What is CVE-2024-20021? +
How severe is CVE-2024-20021? +
What products are affected by CVE-2024-20021? +
How do I check if I'm vulnerable to CVE-2024-20021? +
Related Vulnerabilities
A security vulnerability has been identified in Acer Care Center where the ACCSvc service creates a Named Pipe with a …
NitroSense 3.x before 3.01.3052 contains Local Privilege Escalation (LPE) vulnerability.The program exposes a Windows Named Pipe that uses a custom …
Local privilege escalation potentially allowed an attacker to write an arbitrary file with fully controlled content as a privileged user.
Improper Privilege Management (CWE-269) in `/usr/bin/ltsudo` in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on …
PredatorSense version 3.00.3136 to 3.00.3196 contain Local Privilege Escalation (LPE) vulnerability.The program exposes a Windows Named Pipe that uses a …
A privilege escalation vulnerability in Palo Alto Networks Cortex® XDR Broker VM enables a locally authenticated user to perform actions …