Buffer overflow in Qualcomm products - CVE-2022-22063
Published: December 6, 2022 / Updated: May 4, 2023
Vulnerability identifier: #VU69944
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-22063
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability:
Public exploit is available
Vulnerability details
The vulnerability allows a local application to escalate privileges on the system.
The vulnerability exists due to a boundary error within the Core component caused by improper configuration in boot remapper. A local application can trigger memory corruption and execute arbitrary code with elevated privileges.
Affected software
APQ8096AU
MDM9640
QCA6174A
QCA6574AU
MDM9645
QCA6174
QCA6574A
WCN3990
MDM9640
QCA6174A
QCA6574AU
MDM9645
QCA6174
QCA6574A
WCN3990
How to mitigate CVE-2022-22063
Install updates from vendor's website.