Double Free in MediaTek products - CVE-2022-32614
Published: November 7, 2022
Vulnerability identifier: #VU69010
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-32614
CWE-ID: CWE-415
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local application to escalate privileges on the system.
The vulnerability exists due to a logic error within the audio component. A local application can trigger a double free error and execute arbitrary code with elevated privileges.
Affected software
MT6789
MT6855
MT6879
MT6983
MT8168
MT8365
MT8798
MT6893
MT8797
MT6855
MT6879
MT6983
MT8168
MT8365
MT8798
MT6893
MT8797
How to mitigate CVE-2022-32614
Install updates from vendor's website.