PT-2024-10295 · Google · Android

Published

2024-12-05

·

Updated

2025-01-08

·

CVE-2024-53842

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Android (affected versions not specified)
Description The issue is related to a possible out of bounds write in the cc SendCcImsInfoIndMsg function of the cc MmConManagement.c file. This is due to a missing bounds check, which could lead to remote code execution with no additional execution privileges needed. User interaction is not required for exploitation.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Memory Corruption

Weakness Enumeration

Related Identifiers

BDU:2025-00711
CVE-2024-53842

Affected Products

Android