Description
In wlan STA driver, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00464377; Issue ID: MSV-4905.
CVSS breakdown
CVSS 3.1
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
Affected products
- MediaTek, Inc. / MediaTek chipsetMT7902 – MT7902
- MediaTek, Inc. / MediaTek chipsetMT7920 – MT7920
- MediaTek, Inc. / MediaTek chipsetMT7921 – MT7921
- MediaTek, Inc. / MediaTek chipsetMT7922 – MT7922
- MediaTek, Inc. / MediaTek chipsetMT7925 – MT7925
- MediaTek, Inc. / MediaTek chipsetMT7927 – MT7927