CVE-2024-53838
CVSS 3.1 Score 7.8 of 10 (high)
Details
Published Jan 3, 2025
CWE ID 787
Summary
CVE-2024-53838 is a newly disclosed vulnerability affecting the Exynos_parsing_user_data_registered_itu_t_t35 function in VendorVideoAPI.cpp. The issue involves an incorrect bounds check, which could result in a possible out-of-bounds write. Exploitation of this vulnerability allows for local privilege escalation without the need for additional execution privileges or user interaction.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.