CVE-2024-22098: AVSession has a use after free vulnerability
Published Apr 2, 2024
·Updated
in OpenHarmony v3.2.4 and prior versions allow a local attacker arbitrary code execution in any apps through use after free.
Affected Software
1 affected component
Openatom Openharmony<=3.2.4
Event History
Apr 2, 2024
CVE Published
via MITRE·06:22 AM
Data Sourced
via MITRE·06:22 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-22098?
CVE-2024-22098 has a high severity rating due to its potential for arbitrary code execution.
2
How do I fix CVE-2024-22098?
To fix CVE-2024-22098, upgrade OpenHarmony to version 3.2.5 or later.
3
Which versions of OpenHarmony are affected by CVE-2024-22098?
OpenHarmony v3.2.4 and prior versions are affected by CVE-2024-22098.
4
What type of attack does CVE-2024-22098 allow?
CVE-2024-22098 allows local attackers to execute arbitrary code in any apps.
5
Is remote access needed to exploit CVE-2024-22098?
No, CVE-2024-22098 can be exploited locally, meaning remote access is not required.