CVE-2026-20586
Received Received - Intake

Out-of-Bounds Write in MediaTek vdec Component

Vulnerability report for CVE-2026-20586, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: MediaTek, Inc.

Description

In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS11383899; Issue ID: MSV-9614.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
mediatek vdec to ALPS11383899 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-787 The product writes data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a vulnerability in the vdec component where a missing bounds check could allow an out of bounds write. This might enable remote privilege escalation without needing extra execution privileges. Exploitation requires user interaction.

Impact Analysis

An attacker could exploit this to gain elevated privileges on your system remotely. Since no additional execution privileges are needed, the risk is higher if user interaction is possible.

Compliance Impact

This vulnerability involves a possible out of bounds write in vdec due to missing bounds checks, potentially leading to remote privilege escalation. While the specific impact on compliance standards like GDPR or HIPAA is not detailed in the provided context, such vulnerabilities could pose risks to data integrity and confidentiality, which are key concerns under these regulations.

Mitigation Strategies

Apply the patch identified as ALPS11383899 to address the missing bounds check in vdec. Ensure the update is applied to all affected systems to prevent potential remote privilege escalation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-20586. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart