Symbolic Link Following Vulnerability in MediaTek Mobile Products
CVE-2022-20068
Key Information:
- Vendor
MediaTek
- Vendor
- CVE Published:
- 11 April 2022
What is CVE-2022-20068?
In the mobile_log_d component of MediaTek's products, a vulnerability exists due to improper resolution of symbolic links. This weakness could allow attackers to escalate privileges locally, requiring system execution privileges for exploitation. Importantly, exploitation does not require user interaction, heightening the risk of unauthorized access. A patch is available to mitigate this issue.
Affected Version(s)
MT6731, MT6732, MT6735, MT6737, MT6739, MT6761, MT6762, MT6763, MT6765, MT6768, MT6769, MT6771, MT6779, MT6781, MT6785, MT6795, MT6799, MT6833, MT6853T, MT6873, MT6875, MT6877, MT6880, MT6883, MT6885, MT6889, MT6890, MT6891, MT6893, MT6985, MT8163, MT8167, MT8167S, MT8168, MT8173, MT8175, MT8183, MT8185, MT8321, MT8362A, MT8365, MT8385, MT8666, MT8667, MT8675, MT8735A, MT8735B, MT8765, MT8766, MT8768, MT8786, MT8788, MT8789, MT8791, MT8797 Android 10.0, 11.0, 12.0