In Preloader XFLASH, there is a possible escalation of privilege due to an improper certificate validation. This could lead to local escalation of privilege for an attacker who has physical access to the device with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06160806; Issue ID: ALPS06160806.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Google
Subscribe
|
Android
Subscribe
|
|
Mediatek
Subscribe
|
Mt6580
Subscribe
Mt6735
Subscribe
Mt6739
Subscribe
Mt6761
Subscribe
Mt6763
Subscribe
Mt6765
Subscribe
Mt6768
Subscribe
Mt6769
Subscribe
Mt6771
Subscribe
Mt6779
Subscribe
Mt6781
Subscribe
Mt6785
Subscribe
Mt6799
Subscribe
Mt6833
Subscribe
Mt6853
Subscribe
Mt6873
Subscribe
Mt6875
Subscribe
Mt6877
Subscribe
Mt6885
Subscribe
Mt6891
Subscribe
Mt6893
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-25294 | In Preloader XFLASH, there is a possible escalation of privilege due to an improper certificate validation. This could lead to local escalation of privilege for an attacker who has physical access to the device with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06160806; Issue ID: ALPS06160806. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: MediaTek
Published:
Updated: 2024-08-03T01:55:46.233Z
Reserved: 2021-10-12T00:00:00
Link: CVE-2022-20034
No data.
Status : Modified
Published: 2022-02-09T23:15:17.277
Modified: 2024-11-21T06:41:59.670
Link: CVE-2022-20034
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD