PT-2024-28681 · Unknown · Openharmony

Published

2024-09-01

·

Updated

2024-09-05

·

CVE-2024-39816

CVSS v3.1

8.4

High

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions OpenHarmony versions 4.1.0 and prior
Description The issue allows a local attacker to execute arbitrary code in pre-installed apps through an out-of-bounds write. This poses a security risk to affected systems.
Recommendations For OpenHarmony versions 4.1.0 and prior, update to the latest version as detailed in the remediation guidelines to mitigate the issue. Apply the latest patches and follow the outlined remediation guidelines to safeguard systems.

Fix

Memory Corruption

Weakness Enumeration

Related Identifiers

CVE-2024-39816

Affected Products

Openharmony