Race condition in MediaTek products - CVE-2022-32644
Published: January 3, 2023
Vulnerability identifier: #VU70641
CSH Severity: Low
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-32644
CWE-ID: CWE-362
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a a local application to escalate privileges on the system.
The vulnerability exists due to a race condition within vow component. A local application can exploit the race and gain unauthorized access to sensitive information and escalate privileges on the system.
Affected software
MT6885
MT8797
MT6893
MT6891
MT6883
MT6877
MT6875
MT6873
MT6853
MT8791T
MT8791
MT8781
MT6983
MT6895
MT6789
MT6879
MT6855
MT6833
MT8797
MT6893
MT6891
MT6883
MT6877
MT6875
MT6873
MT6853
MT8791T
MT8791
MT8781
MT6983
MT6895
MT6789
MT6879
MT6855
MT6833
How to mitigate CVE-2022-32644
Install updates from vendor's website.