Out of Bounds Write Vulnerability in Bluetooth by MediaTek
CVE-2022-20027
7.8HIGH
Key Information:
- Vendor
- MediaTek
- Vendor
- CVE Published:
- 9 February 2022
Summary
A vulnerability in Bluetooth by MediaTek allows for a possible out of bounds write due to a missing bounds check. This issue could enable an attacker to escalate their privileges on affected devices without requiring additional execution rights or user interaction. The flaw is documented with Patch ID ALPS06126826 and poses significant security considerations that warrant immediate attention and remediation.
Affected Version(s)
MT8167, MT8175, MT8183, MT8362A, MT8365, MT8385 Android 8.1, 9.0, 10.0, 11.0, 12.0
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved