Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2024-20039

CVE-2024-20039: MediaTek LR12A Modem RCE Vulnerability

CVE-2024-20039 is a remote code execution vulnerability in MediaTek LR12A modem protocol caused by an out-of-bounds write flaw. Attackers can exploit this without user interaction. This article covers technical details, affected versions, impact assessment, and mitigation strategies.

Published:

CVE-2024-20039 Overview

CVE-2024-20039 is an out-of-bounds write vulnerability in the MediaTek modem protocol implementation. The flaw stems from a missing bounds check that allows remote code execution without user interaction. MediaTek tracks the fix under Patch ID MOLY01240012 and Issue ID MSV-1215. The weakness is categorized as [CWE-787] and affects a wide range of MediaTek baseband chipsets used in smartphones, tablets, and IoT devices. Exploitation requires low privileges but no user interaction, and can compromise confidentiality, integrity, and availability of affected devices.

Critical Impact

A remote attacker with low privileges can trigger an out-of-bounds write in the modem protocol handler, leading to remote code execution on the baseband processor across dozens of MediaTek chipset families.

Affected Products

  • MediaTek smartphone SoCs including MT6739, MT6761MT6785, MT6833MT6897, and MT6980MT6990
  • MediaTek tablet and platform SoCs including MT8666MT8798
  • MediaTek modem platforms LR12A, LR13, NR15, NR16, and NR17

Discovery Timeline

  • 2024-04-01 - CVE-2024-20039 published to the National Vulnerability Database
  • April 2024 - MediaTek publishes fix in the April 2024 Product Security Bulletin
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2024-20039

Vulnerability Analysis

The vulnerability resides in the MediaTek modem protocol stack, which runs on the baseband processor and handles cellular signaling. A protocol handler writes data to a buffer without validating that the destination has sufficient capacity. When an attacker supplies input that exceeds the expected size, the write operation crosses the buffer boundary and corrupts adjacent memory.

Because the modem stack processes data received over the air, the out-of-bounds write can be reached through the cellular network path. Successful memory corruption inside the modem process can lead to arbitrary code execution on the baseband, which sits below the application processor and outside the reach of most operating-system defenses.

Root Cause

The root cause is a missing bounds check in a modem protocol parsing routine. The affected code path accepts a length or index from an untrusted message and uses it to write into a fixed-size buffer without verifying that the value falls within allocated bounds. This maps to CWE-787: Out-of-bounds Write.

Attack Vector

The attack vector is network-adjacent through the cellular radio interface. An attacker who can deliver crafted modem protocol messages to a vulnerable device, for example through a rogue base station or compromised network element, can trigger the overflow. No user interaction is required, and the low privilege requirement reflects the attacker's need to interact with the modem interface rather than the operating system.

No public proof-of-concept exploit is available for CVE-2024-20039 at the time of writing. Refer to the MediaTek Product Security Bulletin April 2024 for the vendor's technical description.

Detection Methods for CVE-2024-20039

Indicators of Compromise

  • Unexpected modem crashes, resets, or radio interface restarts on affected MediaTek chipsets
  • Baseband firmware logs showing malformed or oversized protocol messages preceding a fault
  • Devices repeatedly attaching to unknown or unauthorized cell towers with anomalous signaling

Detection Strategies

  • Inventory mobile fleets and cross-reference SoC identifiers against the MediaTek chipset list in the April 2024 bulletin
  • Monitor mobile device management (MDM) telemetry for baseband firmware versions that predate the MOLY01240012 fix
  • Correlate cellular anomalies, such as forced downgrades or rogue base station indicators, with device fault events

Monitoring Recommendations

  • Ingest MDM and endpoint telemetry into a centralized data lake to track patch state across device inventories
  • Alert on baseband crash signatures and modem reset patterns that could indicate exploitation attempts
  • Track vendor security bulletins from MediaTek and downstream OEMs to identify devices still awaiting patches

How to Mitigate CVE-2024-20039

Immediate Actions Required

  • Apply the MediaTek patch identified as MOLY01240012 through the OEM firmware update channel for each affected device model
  • Prioritize patching for high-risk users, executives, and any device that operates in untrusted RF environments
  • Enumerate the fleet against the affected SoC list and escalate devices that have reached end-of-support with the OEM

Patch Information

MediaTek addressed the vulnerability in the April 2024 Product Security Bulletin under Patch ID MOLY01240012 and Issue ID MSV-1215. The fix must be integrated by downstream device vendors and delivered through OEM firmware updates. Refer to the MediaTek Security Bulletin April 2024 for the complete list of patched chipsets and vendor guidance.

Workarounds

  • Disable cellular radios on devices that do not require connectivity until firmware updates arrive
  • Restrict device operation to trusted networks and avoid roaming in areas where rogue base station activity is plausible
  • Replace devices whose OEMs will not ship the MediaTek April 2024 firmware update

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.