PT-2024-26938 · Unknown · Openharmony

Published

2024-07-02

·

Updated

2024-09-09

·

CVE-2024-36260

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenHarmony versions prior to 4.0.0 OpenHarmony version 4.0.0
Description The issue allows a remote attacker to execute arbitrary code in pre-installed apps through an out-of-bounds write.
Recommendations For OpenHarmony versions prior to 4.0.0, update to version 4.0.0 or later. For OpenHarmony version 4.0.0, no specific fix is provided beyond this version, consider this version as the fixed one for previous versions.

Fix

Memory Corruption

Weakness Enumeration

Related Identifiers

CVE-2024-36260

Affected Products

Openharmony