CVE-2022-20063: Medium severity android vulnerability
Published Apr 11, 2022
·Updated
In atf (spm), there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS06171715; Issue ID: ALPS06171715.
Affected Software
9 affected components
Google Android=9.0
Google Android=10.0
MediaTek Mt6765
MediaTek Mt8385
MediaTek Mt8666
MediaTek Mt8667
MediaTek Mt8766
MediaTek Mt8786
MediaTek Mt8788
Event History
Apr 11, 2022
CVE Published
via MITRE·07:37 PM
Data Sourced
via MITRE·07:37 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-20063?
CVE-2022-20063 has a high severity rating due to the potential for local privilege escalation.
2
How do I fix CVE-2022-20063?
To fix CVE-2022-20063, apply the recommended patch identified as ALPS06171715.
3
Which versions of Android are affected by CVE-2022-20063?
CVE-2022-20063 affects Android versions 9.0 and 10.0.
4
What kind of exploitation is possible with CVE-2022-20063?
CVE-2022-20063 allows for a local out of bounds write which can lead to privilege escalation.
5
Is user interaction required to exploit CVE-2022-20063?
Yes, user interaction is necessary for the exploitation of CVE-2022-20063.