CVE-2022-32623

In mdp, there is a possible out of bounds write due to incorrect error handling. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07342114; Issue ID: ALPS07342114.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:*
OR cpe:2.3:h:mediatek:mt6789:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6855:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6879:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6895:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6983:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8168:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8365:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8781:-:*:*:*:*:*:*:*

History

10 Apr 2025, 19:15

Type Values Removed Values Added
CWE CWE-787

21 Nov 2024, 07:06

Type Values Removed Values Added
References () https://corp.mediatek.com/product-security-bulletin/January-2023 - Vendor Advisory () https://corp.mediatek.com/product-security-bulletin/January-2023 - Vendor Advisory
Summary
  • (es) En mdp, existe una posible escritura fuera de los límites debido a un manejo incorrecto de errores. Esto podría conducir a una escalada local de privilegios con permisos de ejecución de System necesarios. La interacción del usuario no es necesaria para la explotación. ID de parche: ALPS07342114; ID del problema: ALPS07342114.

Information

Published : 2023-01-03 21:15

Updated : 2025-04-10 19:15


NVD link : CVE-2022-32623

Mitre link : CVE-2022-32623

CVE.ORG link : CVE-2022-32623


JSON object : View

Products Affected

mediatek

  • mt6855
  • mt8365
  • mt6895
  • mt8168
  • mt8781
  • mt6879
  • mt6983
  • mt6789

google

  • android
CWE
NVD-CWE-Other CWE-787

Out-of-bounds Write