CVE-2024-43061

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Mar 3, 2025
Updated: Mar 6, 2025
CWE ID 416

Summary

CVE-2024-43061 is a newly disclosed vulnerability affecting voice activation functionality in certain HLOS drives. The issue arises when the system attempts to load sound model parameters during voice activation, but the HLOS drive is empty, resulting in memory corruption. This vulnerability could potentially be exploited by an attacker to execute arbitrary code or cause a denial of service. Successful exploitation depends on the attacker's ability to manipulate the voice activation process and trigger the memory corruption condition. Users of the affected HLOS drives are advised to apply the forthcoming patch to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share