Input validation error in MediaTek products - CVE-2022-32592
Published: October 3, 2022
Vulnerability identifier: #VU67847
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2022-32592
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vendor: MediaTek
Affected software:
MT6855
MT6879
MT6895
MT6983
MT8185
MT8321
MT8385
MT8518
MT8666
MT8675
MT8765
MT8768
MT8786
MT8788
MT8789
MT6855
MT6879
MT6895
MT6983
MT8185
MT8321
MT8385
MT8518
MT8666
MT8675
MT8765
MT8768
MT8786
MT8788
MT8789
Detailed vulnerability description
The vulnerability allows a local application to escalate privileges on the system.
The vulnerability exists due to improper input validation within cpu dvfs. A local application can execute arbitrary code with elevated privileges.How to mitigate CVE-2022-32592
Install updates from vendor's website.