CVE-2026-20423

7.1

MediaTek · MediaTek chipset (MT7902, MT7920, MT7921, MT7922, MT7925, MT7927)

A missing bounds check in the MediaTek wlan STA driver leads to an out of bounds write vulnerability, potentially allowing local privilege escalation.

Executive summary

A high-severity out of bounds write vulnerability in MediaTek wlan STA drivers enables local privilege escalation for authenticated users.

Vulnerability

The vulnerability exists due to a missing bounds check in the wlan STA driver, which allows an attacker with low-level user privileges to perform an out of bounds write. This flaw can be exploited by an authenticated local user to achieve privilege escalation without requiring further user interaction.

Business impact

Successful exploitation of this vulnerability allows a local attacker to gain elevated privileges on the host system, potentially leading to full system compromise. Given the CVSS score of 7.1, this represents a significant risk to data confidentiality, integrity, and availability, particularly in environments where untrusted users may have local access to hardware-connected systems.

Remediation

Immediate Action: Consult the MediaTek product security bulletin for March 2026 to identify and apply the specific firmware or driver updates corresponding to Patch ID WCNCR00465314.

Proactive Monitoring: Monitor system logs for unusual driver behavior, kernel crashes, or unexpected privilege escalation events that may indicate exploitation attempts.

Compensating Controls: Restrict local access to systems utilizing the affected MediaTek chipsets to authorized personnel only, and implement kernel-level protections to mitigate potential memory corruption exploits.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Organizations utilizing devices equipped with the affected MediaTek chipsets should prioritize the deployment of vendor-supplied patches as soon as they become available. Given the potential for local privilege escalation, securing the kernel environment and restricting user access remain critical secondary measures until the necessary firmware updates can be applied across the fleet.

More MediaTek CVEs

Sources