CVE-2022-20068: Medium severity android vulnerability
In mobilelogd, there is a possible symbolic link following due to an improper link resolution. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06308907; Issue ID: ALPS06308907.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-20068?
CVE-2022-20068 is a vulnerability in mobile_log_d that allows for symbolic link following and can lead to local escalation of privilege.
What is the severity of CVE-2022-20068?
The severity of CVE-2022-20068 is medium, with a CVSS score of 6.7.
Which software versions are affected by CVE-2022-20068?
CVE-2022-20068 affects Google Android versions 10.0, 11.0, and 12.0.
How can I fix CVE-2022-20068?
To fix CVE-2022-20068, apply the patch provided by the vendor as specified in the reference link: https://corp.mediatek.com/product-security-bulletin/April-2022.
Is user interaction required for exploiting CVE-2022-20068?
No, user interaction is not needed for exploiting CVE-2022-20068.