CVE-2025-20800

7.8

MediaTek · MediaTek chipset

A missing bounds check in the mminfra component of various MediaTek chipsets allows for an out of bounds write, potentially leading to local privilege escalation.

Executive summary

A critical out of bounds write vulnerability in MediaTek chipsets enables local privilege escalation for attackers who have already obtained system-level access.

Vulnerability

The flaw is an out of bounds write (CWE-787) within the mminfra component. Exploitation requires an attacker to already possess system privileges, at which point they can escalate their standing without user interaction.

Business impact

This vulnerability carries a CVSS score of 7.8, reflecting a high-severity risk to system integrity and confidentiality. While the prerequisite of existing system access limits the scope, successful exploitation allows an attacker to bypass remaining security controls, potentially leading to total system compromise and unauthorized data access.

Remediation

Immediate Action: Apply the vendor-provided security update associated with Patch ID ALPS10267349 as detailed in the January 2026 MediaTek security bulletin.

Proactive Monitoring: Monitor system logs for unusual behavior or unauthorized attempts to access restricted memory regions or system-level processes.

Compensating Controls: Ensure that system-level access is strictly controlled and that least-privilege principles are enforced to prevent attackers from reaching the state required to trigger this vulnerability.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the high impact on system security, administrators must prioritize the application of the official MediaTek patch. Organizations using affected hardware should verify their current firmware versions against the January 2026 security bulletin and ensure that vendor-supplied updates are deployed across all managed devices to effectively mitigate this escalation risk.

More MediaTek CVEs

Sources