CVE-2025-20725
7.5MediaTek · ims service
A missing bounds check in the MediaTek ims service allows for an out of bounds write, potentially leading to remote privilege escalation without user interaction.
Executive summary
A critical out of bounds write vulnerability in the MediaTek ims service could allow an attacker to achieve remote privilege escalation by leveraging a rogue base station.
Vulnerability
The vulnerability is an out of bounds write (CWE-787) occurring within the ims service. An attacker controlling a rogue base station can trigger this flaw to achieve remote privilege escalation without requiring user interaction or additional execution privileges.
Business impact
The ability to achieve remote privilege escalation poses a significant risk to mobile device integrity and user data privacy. Given the CVSS score of 7.5, this high severity vulnerability could result in full system compromise, unauthorized access to sensitive information, or the installation of malicious software. Organizations relying on affected MediaTek-based hardware must prioritize remediation to prevent potential exploitation in mobile environments.
Remediation
Immediate Action: Apply the vendor-provided security update (Patch ID: MOLY01671924) as released by MediaTek in their November 2025 security bulletin.
Proactive Monitoring: Monitor device logs for unexpected service crashes or anomalous behavior in the ims service, which may indicate attempted exploitation.
Compensating Controls: Ensure device firmware is kept up to date and avoid connecting to untrusted or public cellular networks where rogue base station attacks are more likely to occur.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
This vulnerability represents a high-risk security flaw that facilitates remote privilege escalation. Organizations and users should immediately verify their device modem firmware versions against the MediaTek November 2025 security bulletin and apply the necessary patches. Failure to remediate this issue leaves devices vulnerable to compromise if they connect to malicious cellular infrastructure.