CVE-2024-0033
CVSS 3.1 Score 7.8 of 10 (high)
Details
Published Feb 16, 2024
Updated: Dec 16, 2024
CWE ID 122
CWE ID 787
Summary
CVE-2024-0033 is a newly identified vulnerability affecting multiple functions in ashmem-dev.cpp. The issue stems from a heap buffer overflow, which potentially results in a missing seal. This condition can be exploited to escalate local privileges without requiring any additional execution privileges or user interaction.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Android