CVE-2024-49737

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Jan 21, 2025
Updated: Jan 22, 2025
CWE ID 276

Summary

CVE-2024-49737 is a newly discovered vulnerability affecting the WindowOrganizerController.java in an unspecified software. This issue stems from a logic error in the applyTaskFragmentOperation function, which could potentially allow an attacker to launch arbitrary activities as the system UID. This escalation of privilege occurs without the requirement for additional execution privileges or user interaction.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share