#VU69000 Buffer overflow in MediaTek products - CVE-2022-21778
Published: November 7, 2022
Vulnerability identifier: #VU69000
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2022-21778
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerable software:
MT6771
MT8168
MT8175
MT8183
MT8365
MT8385
MT8788
MT6779
MT6785
MT6853
MT6853T
MT6873
MT6877
MT6885
MT6891
MT6893
MT6771
MT8168
MT8175
MT8183
MT8365
MT8385
MT8788
MT6779
MT6785
MT6853
MT6853T
MT6873
MT6877
MT6885
MT6891
MT6893
Software vendor:
MediaTek
MediaTek
Description
The vulnerability allows a local application to escalate privileges on the system.
The vulnerability exists due to a boundary error in vpu. A local application can trigger memory corruption and execute arbitrary code with elevated privileges.
Remediation
Install updates from vendor's website.