Race condition in MediaTek products - CVE-2022-32648

 

Race condition in MediaTek products - CVE-2022-32648

Published: January 3, 2023


Vulnerability identifier: #VU70650
CSH Severity: Low
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-32648
CWE-ID: CWE-362
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local application to escalate privileges on the system.

The vulnerability exists due to a race condition. A local application can exploit the race and gain unauthorized access to sensitive information and escalate privileges on the system.


Affected software

MT6735
MT6737
MT6739
MT6753
MT6757
MT6761
MT6763
MT6765
MT6768
MT6771
MT6789
MT6779
MT6785

How to mitigate CVE-2022-32648

Install updates from vendor's website.


External References

Related Security Bulletins