Memory Corruption Vulnerability in Mediatek Products
CVE-2022-20052

6.5MEDIUM

Summary

The vulnerability in Mediatek's mdp involves a potential memory corruption due to a use after free condition. This flaw could allow a malicious actor to escalate local privileges, granting them elevated system execution capabilities. Exploitation requires user interaction, necessitating careful handling of the affected systems. Patches are available to mitigate this risk, stressing the importance of timely updates to secure environments.

Affected Version(s)

MT6580, MT6735, MT6737, MT6739, MT6750, MT6753, MT6755, MT6762, MT6763, MT6765, MT6768, MT6769, MT6771, MT6779, MT6781, MT6785, MT6833, MT6853, MT6853T, MT6873, MT6877, MT6885, MT6890, MT6891, MT6893, MT8163, MT8167, MT8167S, MT8168, MT8173, MT8175, MT8183, MT8321, MT8362A, MT8365, MT8385, MT8666, MT8667, MT8735A, MT8735B, MT8765, MT8766, MT8768, MT8786, MT8788 Android 11.0, 12.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.