Out of Bounds Write Vulnerability in MediaTek Wifi Driver
CVE-2022-26438

6.7MEDIUM

Summary

An out of bounds write vulnerability exists in the MediaTek wifi driver due to a missing bounds check. This vulnerability may allow a local attacker to escalate privileges without the need for user interaction, potentially leading to unauthorized operations with elevated system execution privileges. It is crucial to apply the necessary patches to mitigate this issue, as the impact could be significant if exploited.

Affected Version(s)

MT7603, MT7610, MT7612, MT7613, MT7615, MT7620, MT7622, MT7628, MT7629, MT7915, MT7916, MT7986, MT8981 7.6.2.3

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.