PT-2024-33519 · Samsung · Galaxy S24

Chao Ma

·

Published

2024-11-05

·

Updated

2024-11-13

·

CVE-2024-49408

CVSS v3.1

6.7

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Galaxy S24 versions prior to Firmware update Sep-2024 Release
Description The issue is an out-of-bounds write in the usb driver, allowing local attackers to write out-of-bounds memory. This requires system privilege to trigger.
Recommendations For Galaxy S24 versions prior to Firmware update Sep-2024 Release, update to the Sep-2024 Release or later to resolve the issue. As a temporary workaround, consider restricting access to the usb driver to minimize the risk of exploitation.

Fix

Memory Corruption

Weakness Enumeration

Related Identifiers

CVE-2024-49408

Affected Products

Galaxy S24