Undefined Behavior in Wi-Fi Driver by MediaTek Leading to Local Escalation of Privilege
CVE-2022-32657
6.7MEDIUM
Key Information:
- Vendor
- MediaTek
- Vendor
- CVE Published:
- 3 January 2023
Summary
A vulnerability in the Wi-Fi driver of MediaTek products arises from improper error handling, resulting in potential undefined behavior. This may permit local escalation of privileges, allowing an attacker to execute actions with elevated system rights without any user interaction. The issue highlights the importance of robust error management in driver software to mitigate risks associated with unauthorized access.
Affected Version(s)
MT7603, MT7613, MT7615, MT7622, MT7628, MT7629, MT7915, MT7916, MT7981, MT7986 7.6.6.0
References
CVSS V3.1
Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved