#VU70643 Race condition in MediaTek products - CVE-2022-32645
Published: January 3, 2023
Vulnerability identifier: #VU70643
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2022-32645
CWE-ID: CWE-362
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerable software:
MT6789
MT6833
MT6855
MT6879
MT6895
MT6983
MT8781
MT8791
MT8791T
MT6853
MT6873
MT6875
MT6877
MT6883
MT6885
MT6891
MT6893
MT8797
MT6789
MT6833
MT6855
MT6879
MT6895
MT6983
MT8781
MT8791
MT8791T
MT6853
MT6873
MT6875
MT6877
MT6883
MT6885
MT6891
MT6893
MT8797
Software vendor:
MediaTek
MediaTek
Description
The vulnerability allows a local application to escalate privileges on the system.
The vulnerability exists due to a race condition within vow component. A local application can exploit the race and gain unauthorized access to sensitive information and escalate privileges on the system.
Remediation
Install updates from vendor's website.