#VU66970 undefined in MediaTek products - CVE-2022-26461
Published: September 5, 2022
Vulnerability identifier: #VU66970
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2022-26461
CWE-ID: CWE-475
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerable software:
MT6833
MT6855
MT6879
MT6895
MT6983
MT8791
MT6853
MT6873
MT6877
MT6883
MT6885
MT6889
MT6893
MT8797
MT6833
MT6855
MT6879
MT6895
MT6983
MT8791
MT6853
MT6873
MT6877
MT6883
MT6885
MT6889
MT6893
MT8797
Software vendor:
MediaTek
MediaTek
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to undefined behavior for input to api in vow, which leads to security restrictions bypass and privilege escalation.
Remediation
Install updates from vendor's website.