{"id":"CVE-2020-0069","vendor_project":"MediaTek","product":"Multiple Chipsets","vulnerability_name":"Mediatek Multiple Chipsets Insufficient Input Validation Vulnerability","date_added":"2021-11-03","due_date":"2022-05-03","known_ransomware_use":"Unknown","short_description":"Multiple MediaTek chipsets contain an insufficient input validation vulnerability and have missing SELinux restrictions in the Command Queue drivers ioctl handlers. This causes an out-of-bounds write leading to privilege escalation. This vulnerability was observed chained with CVE-2019-2215 and CVE-2020-0041 under exploit chain \"AbstractEmu.\"","required_action":"Apply updates per vendor instructions.","cwes":"CWE-787","cvss_version":"3.1","cvss_severity":"HIGH","cvss_vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","nvd_published":"2020-03-10","nvd_status":"Analyzed","epss":0.0137,"epss_percentile":0.70736,"cvss_score":7.8,"days_published_to_kev":603,"source":"https://data.cybermax-tools.workers.dev/cve/CVE-2020-0069","by":"CyberMax"}