GPU PDMA memory corruption in Windows driver - missing permission check
CVE-2025-20788 Published on December 2, 2025
In GPU pdma, there is a possible memory corruption due to a missing permission check. This could lead to local denial of service with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS10117735; Issue ID: MSV-4539.
Vulnerability Analysis
CVE-2025-20788 is exploitable with local system access, requires user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality, with no impact on integrity and availability.
Weakness Type
Register Interface Allows Software Access to Sensitive Data or Security Settings
Memory-mapped registers provide access to hardware functionality from software and if not properly secured can result in loss of confidentiality and integrity.
Products Associated with CVE-2025-20788
Want to know whenever a new CVE is published for MediaTek Mt8196? stack.watch will email you.
Affected Versions
MediaTek, Inc. MT6991, MT8196 Version Android 15.0, is affected by CVE-2025-20788Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.