CVE-2022-20043: High severity android vulnerability
Published Feb 9, 2022
·Updated
In Bluetooth, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06148177; Issue ID: ALPS06148177.
Affected Software
11 affected components
Google Android=8.1
Google Android=9.0
Google Android=10.0
Google Android=11.0
Google Android=12.0
MediaTek Mt8167
MediaTek Mt8175
MediaTek Mt8183
MediaTek Mt8362a
MediaTek Mt8365
MediaTek Mt8385
Event History
Feb 9, 2022
CVE Published
via MITRE·10:05 PM
Data Sourced
via MITRE·10:05 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-20043?
CVE-2022-20043 is classified as a high-severity vulnerability as it allows for local escalation of privilege without user interaction.
2
Who is affected by CVE-2022-20043?
CVE-2022-20043 affects specific versions of Google Android, including 8.1, 9.0, 10.0, 11.0, and 12.0.
3
How do I fix CVE-2022-20043?
To fix CVE-2022-20043, apply the patch identified by Patch ID ALPS06148177.
4
Does CVE-2022-20043 require user interaction to exploit?
No, CVE-2022-20043 can be exploited without any user interaction.
5
What type of vulnerability is CVE-2022-20043?
CVE-2022-20043 is a privilege escalation vulnerability in the Bluetooth component.