CVE-2024-39831

CVSS 3.1 Score 6.7 of 10 (medium)

Details

Published Oct 8, 2024
Updated: Oct 16, 2024
CWE ID 416

Summary

CVE-2024-39831 is a vulnerability affecting OpenHarmony v4.1.0 that grants local attackers with high privileges the ability to execute arbitrary code in pre-installed apps. This occurs due to a use-after-free condition, where memory that has already been freed is reused, allowing the attacker to inject malicious code and gain unauthorized access. The impact of this vulnerability is significant, as an attacker can exploit it to take control of the system and potentially cause substantial damage. Users are advised to update their OpenHarmony installation to a newer, patched version as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share