CVE-2022-20074: Medium severity android vulnerability
In preloader (partition), there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, for an attacker who has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS06183301; Issue ID: ALPS06183301.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-20074?
CVE-2022-20074 is a vulnerability in the preloader (partition) of certain software that allows an attacker with physical access to the device to perform an out of bounds write, potentially leading to local escalation of privilege.
What is the severity of CVE-2022-20074?
CVE-2022-20074 has a severity rating of 6.6 (Medium).
Which software versions are affected by CVE-2022-20074?
Google Android versions 10.0, 11.0, and 12.0 are affected by CVE-2022-20074.
What is the impact of CVE-2022-20074?
CVE-2022-20074 can allow an attacker to escalate their privilege level on the affected device with physical access.
How can CVE-2022-20074 be mitigated?
Apply the patch provided by the software vendor to fix CVE-2022-20074.