CVE-2022-21744: Critical severity Google Android vulnerability
In Modem 2G RR, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution when decoding GPRS Packet Neighbour Cell Data (PNCD) improper neighbouring cell size with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00810064; Issue ID: ALPS06641626.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-21744?
CVE-2022-21744 is rated as critical due to its potential to allow remote code execution.
How do I fix CVE-2022-21744?
To fix CVE-2022-21744, apply the latest security patches provided by the affected vendors, such as Google and MediaTek.
Which products are affected by CVE-2022-21744?
CVE-2022-21744 affects certain versions of Google Android and several MediaTek modem products.
What are the risks associated with CVE-2022-21744?
The risks associated with CVE-2022-21744 include potential remote code execution, which could compromise device security.
Is user interaction required to exploit CVE-2022-21744?
No, user interaction is not required to exploit CVE-2022-21744.