First published: Tue May 07 2024(Updated: )
in OpenHarmony v4.0.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through use after free or cause DOS through NULL pointer dereference.
Credit: scy@openharmony.io
Affected Software | Affected Version | How to fix |
---|---|---|
Openatom Openharmony | <4.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-23808 has been classified as a high severity vulnerability due to its potential for arbitrary code execution.
To fix CVE-2024-23808, you should update OpenHarmony to version 4.0.1 or later.
CVE-2024-23808 can be exploited through local attacks that leverage use after free vulnerabilities or cause denial of service via NULL pointer dereference.
CVE-2024-23808 affects OpenHarmony v4.0.0 and prior versions.
Local attackers targeting users of pre-installed apps on affected versions of OpenHarmony may be impacted by CVE-2024-23808.