CVE-2024-24581: Arkcompiler runtime has an out-of-bounds write vulnerability
Published Apr 2, 2024
·Updated
in OpenHarmony v4.0.0 and prior versions allow a local attacker arbitrary code execution through out-of-bounds write.
Affected Software
2 affected components
OpenHarmony OpenHarmony<4.0.0
Openatom Openharmony>=3.2<=4.0
Event History
Apr 2, 2024
CVE Published
via MITRE·06:23 AM
Data Sourced
via MITRE·06:23 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-24581?
CVE-2024-24581 is rated as critical due to its potential for arbitrary code execution.
2
How do I fix CVE-2024-24581?
To mitigate CVE-2024-24581, update OpenHarmony to version 4.0.1 or later.
3
Who is affected by CVE-2024-24581?
CVE-2024-24581 affects all versions of OpenHarmony prior to 4.0.1.
4
What type of vulnerability is CVE-2024-24581?
CVE-2024-24581 is classified as a local privilege escalation vulnerability allowing arbitrary code execution.
5
Can CVE-2024-24581 be exploited remotely?
CVE-2024-24581 requires local access to exploit, thus it cannot be exploited remotely.