Integer Overflow Vulnerability in Apusys Driver by MediaTek
CVE-2022-21761

4.4MEDIUM

What is CVE-2022-21761?

The Apusys driver from MediaTek contains an integer overflow vulnerability that can potentially cause a system crash, leading to a local denial of service. This issue does not require user interaction for exploitation, which intensifies the risk to system integrity. It's essential for users and administrators to apply the necessary patches to mitigate this vulnerability effectively.

Affected Version(s)

MT6853, MT6853T, MT6873, MT6875, MT6877, MT6883, MT6885, MT6889, MT6891, MT6893, MT9636, MT9638, MT9666 Android 11.0

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.