Improper Synchronization in MediaTek products - CVE-2023-32832
Published: November 7, 2023
Vulnerability identifier: #VU82802
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-32832
CWE-ID: CWE-662
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local application to execute arbitrary code.
The vulnerability exists due to a race condition within video. A local application can execute arbitrary code.
Affected software
MT6883
MT6885
MT6889
MT6893
MT8797
MT6895
MT6983
MT6985
MT8798
Google Android
MT6885
MT6889
MT6893
MT8797
MT6895
MT6983
MT6985
MT8798
Google Android
How to mitigate CVE-2023-32832
Install security update from vendor's website.
Google Android - addressed in versions 11 2023-11-05, 12L 2023-11-05, 12 2023-11-05, 13 2023-11-05, 14 2023-11-05