CVE-2022-20059: Medium severity android vulnerability
In preloader (usb), there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, for an attacker who has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS06160806; Issue ID: ALPS06160781.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-20059?
CVE-2022-20059 is a vulnerability in preloader (usb) that allows for a possible out of bounds write, leading to local escalation of privilege.
How severe is CVE-2022-20059?
CVE-2022-20059 has a severity rating of 6.6 (medium).
Which software versions are affected by CVE-2022-20059?
Google Android versions 10.0, 11.0, and 12.0 are affected by CVE-2022-20059.
Is Mediatek Mt6761 vulnerable to CVE-2022-20059?
No, Mediatek Mt6761 is not vulnerable to CVE-2022-20059.
How can I patch CVE-2022-20059?
To patch CVE-2022-20059, apply the patch provided by the vendor or update your Google Android software to a non-vulnerable version.