Out of Bounds Write Vulnerability in MediaTek Wi-Fi Driver
CVE-2022-26444

6.7MEDIUM

Summary

The MediaTek Wi-Fi driver has a vulnerability that results from a missing bounds check, which permits an out-of-bounds write. This flaw could allow an attacker with local access to escalate privileges to system-level execution. The vulnerability does not require user interaction for exploitation, making it a significant risk. Affected products should be promptly updated with the patch provided by MediaTek to mitigate this issue.

Affected Version(s)

MT7603, MT7610, MT7612, MT7613, MT7615, MT7620, MT7622, MT7628, MT7629, MT7915, MT7916, MT7986, MT8981 7.6.2.3

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.