Out of Bounds Write Vulnerability in MediaTek Power Service
CVE-2022-21759

6.7MEDIUM

Summary

A vulnerability has been identified within MediaTek's Power Service that allows an out of bounds write due to a missing bounds check. This issue could be exploited to achieve local escalation of privileges, granting an attacker system execution capabilities without the need for user interaction. It is crucial for users of the affected products to apply remediation steps provided in the official security bulletin to mitigate the risks associated with this vulnerability.

Affected Version(s)

MT6580, MT6735, MT6739, MT6761, MT6765, MT6768, MT6769, MT6771, MT6779, MT6781, MT6785, MT6833, MT6853, MT6873, MT6875, MT6877, MT6879, MT6885, MT6891, MT6893, MT6895, MT6983, MT8167, MT8167S, MT8168, MT8173, MT8185, MT8321, MT8362A, MT8365, MT8385, MT8666, MT8675, MT8765, MT8766, MT8768, MT8786, MT8788, MT8789, MT8791, MT8797 Android 11.0, 12.0

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.