Out of Bounds Write Vulnerability in MediaTek USB Preloader
CVE-2022-20073

6.6MEDIUM

What is CVE-2022-20073?

An out of bounds write vulnerability exists in the USB Preloader of MediaTek devices due to an integer underflow. This flaw allows potential local privilege escalation for attackers possessing physical access to the vulnerable device. User interaction is required to exploit this vulnerability, making it crucial for users to be aware of physical access risks and implement necessary security measures.

Affected Version(s)

MT2601, MT6580, MT6735, MT6739, MT6761, MT6763, MT6765, MT6768, MT6771, MT6779, MT6781, MT6785, MT6799, MT6833, MT6873, MT6877, MT6885, MT6893, MT8163, MT8167, MT8167S, MT8168, MT8173, MT8175, MT8183, MT8185, MT8321, MT8362A, MT8365, MT8385, MT8666, MT8667, MT8675, MT8695, MT8696, MT8765, MT8766, MT8768, MT8786, MT8788, MT8789, MT8791, MT8797 Android 10.0, 11.0, 12.0

References

CVSS V3.1

Score:
6.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.