First published: Tue Dec 03 2024(Updated: )
in OpenHarmony v4.1.1 and prior versions allow a local attacker cause the common permission is upgraded to root through use after free.
Credit: scy@openharmony.io
Affected Software | Affected Version | How to fix |
---|---|---|
Openatom Openharmony | <=4.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-10074 is classified as a high severity vulnerability due to its potential impact on system permissions.
To fix CVE-2024-10074, upgrade OpenHarmony to version 4.1.2 or later.
CVE-2024-10074 affects all versions of OpenHarmony up to and including 4.1.1.
CVE-2024-10074 allows a local attacker to escalate permissions to root through a use-after-free vulnerability.
CVE-2024-10074 is considered a local vulnerability requiring physical or authenticated access to the device.