CVE-2024-10074: Liteos_a has an use after free vulnerability
Published Dec 3, 2024
·Updated
in OpenHarmony v4.1.1 and prior versions allow a local attacker cause the common permission is upgraded to root through use after free.
Affected Software
1 affected component
Openatom Openharmony<=4.1.1
Event History
Dec 3, 2024
CVE Published
via MITRE·12:15 PM
Data Sourced
via MITRE·12:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-10074?
CVE-2024-10074 is classified as a high severity vulnerability due to its potential impact on system permissions.
2
How do I fix CVE-2024-10074?
To fix CVE-2024-10074, upgrade OpenHarmony to version 4.1.2 or later.
3
Who is affected by CVE-2024-10074?
CVE-2024-10074 affects all versions of OpenHarmony up to and including 4.1.1.
4
What does CVE-2024-10074 allow an attacker to do?
CVE-2024-10074 allows a local attacker to escalate permissions to root through a use-after-free vulnerability.
5
Is CVE-2024-10074 a remote or local vulnerability?
CVE-2024-10074 is considered a local vulnerability requiring physical or authenticated access to the device.