Undefined Behavior in Wi-Fi Driver by MediaTek Leading to Local Escalation of Privilege
CVE-2022-32657

6.7MEDIUM

Key Information:

Summary

A vulnerability in the Wi-Fi driver of MediaTek products arises from improper error handling, resulting in potential undefined behavior. This may permit local escalation of privileges, allowing an attacker to execute actions with elevated system rights without any user interaction. The issue highlights the importance of robust error management in driver software to mitigate risks associated with unauthorized access.

Affected Version(s)

MT7603, MT7613, MT7615, MT7622, MT7628, MT7629, MT7915, MT7916, MT7981, MT7986 7.6.6.0

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.