CVE-2024-0045
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Mar 11, 2024
Updated: Dec 17, 2024
CWE ID 125
CWE ID 20
Summary
CVE-2024-0045 is a newly disclosed cybersecurity vulnerability affecting smp_act.cc in the SMP (Simple Mail Transfer Protocol) subsystem. The issue lies in the function smp_proc_sec_req, where input validation is insufficient, resulting in a possible out-of-bounds read. Attackers can exploit this flaw to disclose sensitive information remotely, bypassing the need for additional execution privileges. No user interaction is required to trigger this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Android