Out of Bounds Write Vulnerability in Preloader by MediaTek
CVE-2022-20069

6.6MEDIUM

Summary

A vulnerability exists in MediaTek's Preloader (USB) that allows for a possible out of bounds write due to an integer overflow. This issue poses a risk of local privilege escalation for attackers who possess physical access to the affected device. Exploitation requires user interaction, making awareness and caution essential to protect sensitive data and device integrity. The vulnerability has been documented in the MediaTek product security bulletin.

Affected Version(s)

MT6580, MT6735, MT6739, MT6761, MT6762, MT6763, MT6765, MT6768, MT6769, MT6771, MT6779, MT6781, MT6785, MT6799, MT6833, MT6853, MT6853T, MT6873, MT6877, MT6885, MT6893, MT6983, MT8167, MT8167S, MT8168, MT8173, MT8175, MT8183, MT8185, MT8321, MT8362A, MT8365, MT8385, MT8666, MT8667, MT8675, MT8695, MT8696, MT8765, MT8766, MT8768, MT8786, MT8788, MT8789, MT8791, MT8797 Android 10.0, 11.0, 12.0

References

CVSS V3.1

Score:
6.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.