Out-of-bounds write in MediaTek products - CVE-2022-32632

 

Out-of-bounds write in MediaTek products - CVE-2022-32632

Published: December 5, 2022


Vulnerability identifier: #VU69901
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-32632
CWE-ID: CWE-787
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local application to escalate privileges on the system.

The vulnerability exists due to a boundary error when processing untrusted input within the Wi-Fi subsystem. A local application can trigger an out-of-bounds write and execute arbitrary code with elevated privileges.


Affected software

MT8695
MT7933
MT8168
MT8365
MT8518
MT8532
MT8666
MT8667
MT8675
MT7921
MT8696
MT8766
MT8768
MT8786
MT8789
MT8791
MT6580
MT7902
MT7668
MT7663
MT6983
MT6833
MT6771
MT6768
MT6765
MT6735
MT8797
MT6885
MT6877
MT6873
MT6853
MT6785
MT6779

How to mitigate CVE-2022-32632

Install updates from vendor's website.


External References

Related Security Bulletins