Out-of-bounds write in MediaTek products - CVE-2022-32637
Published: January 3, 2023
Vulnerability identifier: #VU70630
CSH Severity: Low
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-32637
CWE-ID: CWE-787
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local application to escalate privileges on the system.
The vulnerability exists due to a boundary error within hevc decoder component. A local application can trigger out-of-bounds write and escalate privileges on the system.
Affected software
MT6781
MT6785
MT6853
MT6853T
MT6873
MT6883
MT6885
MT6889
MT6833
MT8185
MT8789
Google Android
MT6785
MT6853
MT6853T
MT6873
MT6883
MT6885
MT6889
MT6833
MT8185
MT8789
Google Android
How to mitigate CVE-2022-32637
Install updates from vendor's website.
Google Android - addressed in versions 10 2023-01-05, 11 2023-01-05, 12L 2023-01-05, 12 2023-01-05, 13 2023-01-05