Out of Bounds Write Vulnerability in Mediatek WLAN Driver
CVE-2022-21753

6.7MEDIUM

What is CVE-2022-21753?

The Mediatek WLAN driver contains a vulnerability that allows for an out of bounds write due to insufficient bounds checking. This flaw could potentially lead to local privilege escalation, allowing an attacker with system execution privileges to exploit the issue without requiring user interaction. Proper patches, identified as ALPS06493873 and ALPS06493899, have been initiated to mitigate the risks associated with this vulnerability. For detailed information, refer to the product security bulletin from Mediatek.

Affected Version(s)

MT6580, MT6735, MT6739, MT6761, MT6765, MT6768, MT6771, MT6779, MT6781, MT6785, MT6833, MT6853, MT6873, MT6877, MT6879, MT6883, MT6885, MT6889, MT6893, MT6895, MT6983, MT8167S, MT8168, MT8175, MT8183, MT8185, MT8362A, MT8365, MT8385, MT8667, MT8675, MT8695, MT8696, MT8766, MT8768, MT8786, MT8788, MT8789, MT8797 Android 11.0, 12.0

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.