Permissions, Privileges, and Access Controls in MediaTek products - CVE-2022-26473
Published: October 3, 2022
Vulnerability identifier: #VU67841
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-26473
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local application to escalate privileges on the system.
The vulnerability exists due to improper locking within the vdec fmt component. A local application with System execution permissions can execute arbitrary code.Affected software
MT6789
MT6855
MT6879
MT6895
MT6983
MT8168
MT8365
MT8695
MT8696
MT8798
MT6855
MT6879
MT6895
MT6983
MT8168
MT8365
MT8695
MT8696
MT8798
How to mitigate CVE-2022-26473
Install updates from vendor's website.