Symbolic Link Following Vulnerability in MediaTek Mobile Products
CVE-2022-20068
Key Information:
- Vendor
- MediaTek
- Vendor
- CVE Published:
- 11 April 2022
Summary
In the mobile_log_d component of MediaTek's products, a vulnerability exists due to improper resolution of symbolic links. This weakness could allow attackers to escalate privileges locally, requiring system execution privileges for exploitation. Importantly, exploitation does not require user interaction, heightening the risk of unauthorized access. A patch is available to mitigate this issue.
Affected Version(s)
MT6731, MT6732, MT6735, MT6737, MT6739, MT6761, MT6762, MT6763, MT6765, MT6768, MT6769, MT6771, MT6779, MT6781, MT6785, MT6795, MT6799, MT6833, MT6853T, MT6873, MT6875, MT6877, MT6880, MT6883, MT6885, MT6889, MT6890, MT6891, MT6893, MT6985, MT8163, MT8167, MT8167S, MT8168, MT8173, MT8175, MT8183, MT8185, MT8321, MT8362A, MT8365, MT8385, MT8666, MT8667, MT8675, MT8735A, MT8735B, MT8765, MT8766, MT8768, MT8786, MT8788, MT8789, MT8791, MT8797 Android 10.0, 11.0, 12.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved