PT-2024-28681 · Unknown · Openharmony
Published
2024-09-01
·
Updated
2024-09-05
·
CVE-2024-39816
CVSS v3.1
8.4
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
OpenHarmony versions 4.1.0 and prior
Description
The issue allows a local attacker to execute arbitrary code in pre-installed apps through an out-of-bounds write. This poses a security risk to affected systems.
Recommendations
For OpenHarmony versions 4.1.0 and prior, update to the latest version as detailed in the remediation guidelines to mitigate the issue. Apply the latest patches and follow the outlined remediation guidelines to safeguard systems.
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openharmony