Out of Bounds Write Vulnerability in MediaTek Video Decoder
CVE-2022-20048
7.8HIGH
Key Information:
- Vendor
MediaTek
- Vendor
- CVE Published:
- 10 March 2022
What is CVE-2022-20048?
A vulnerability exists in the MediaTek video decoder that allows for an out of bounds write due to a missing bounds check. This flaw could enable local users to escalate privileges without needing any additional execution privileges. Notably, this vulnerability can be exploited without user interaction, raising concerns regarding potential unauthorized access and system integrity. The security flaw has been documented under Patch ID ALPS05917502.
Affected Version(s)
MT5816, MT5835, MT6885, MT6893, MT9900, MT9901, MT9950, MT9969, MT9970, MT9980 Android 10.0, 11.0, 12.0