Out of Bounds Write Vulnerability in MediaTek ISP
CVE-2022-32616
6.7MEDIUM
Summary
In MediaTek ISP, an out of bounds write vulnerability exists due to uninitialized data. This flaw can potentially allow an attacker to escalate privileges locally, granting them system execution capabilities. Notably, user interaction is not required for exploitation, amplifying the risk associated with this vulnerability. A patch has been issued to address this issue, identified by Patch ID ALPS07341258.
Affected Version(s)
MT6983, MT8871, MT8891 Android 12.0
References
CVSS V3.1
Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved