Error Handling in MediaTek products - CVE-2022-32657
Published: January 4, 2023 / Updated: January 4, 2023
Vulnerability identifier: #VU70672
CSH Severity: Low
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-32657
CWE-ID: CWE-388
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local application to escalate privileges on the system.
The vulnerability exists due to an error handling within Wi-Fi driver. A local application can trigger error handling and escalate privileges on the system.
Affected software
MT7603
MT7613
MT7615
MT7622
MT7628
MT7629
MT7915
MT7916
MT7981
MT7986
MT7613
MT7615
MT7622
MT7628
MT7629
MT7915
MT7916
MT7981
MT7986
How to mitigate CVE-2022-32657
Install updates from vendor's website.