In netdiag, there is a possible symbolic link following due to an improper link resolution. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06308877; Issue ID: ALPS06308877.
References
Link | Resource |
---|---|
https://corp.mediatek.com/product-security-bulletin/May-2022 | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2022-05-03 13:15
Updated : 2022-05-10 13:10
NVD link : CVE-2022-20085
Mitre link : CVE-2022-20085
JSON object : View
CWE
CWE-59
Improper Link Resolution Before File Access ('Link Following')
Products Affected
mediatek
- mt6779
- mt8786
- mt6757ch
- mt6580
- mt6891
- mt8766
- mt6889
- mt8385
- mt8791
- mt6757
- mt6877
- mt6781
- mt8765
- mt6771
- mt6753
- mt8365
- mt8666
- mt8797
- mt6765
- mt6762
- mt6785
- mt8789
- mt6853
- mt6768
- mt8167s
- mt8173
- mt6757cd
- mt8696
- mt6833
- mt6735
- mt6883
- mt6885
- mt8321
- mt6763
- mt8788
- mt6755s
- mt6893
- mt6769
- mt8362a
- mt6757c
- mt6873
- mt6731
- mt6750s
- mt6761
- mt8168
- mt8175
- mt8768
- mt6853t
- mt8167
- mt8675
- mt6875
- mt8185
- android