First published: Tue Apr 02 2024(Updated: )
in OpenHarmony v4.0.0 and prior versions allow a local attacker arbitrary code execution through out-of-bounds write.
Credit: scy@openharmony.io
Affected Software | Affected Version | How to fix |
---|---|---|
Openharmony Openharmony | <4.0.0 | |
Openatom Openharmony | >=3.2<=4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-24581 is rated as critical due to its potential for arbitrary code execution.
To mitigate CVE-2024-24581, update OpenHarmony to version 4.0.1 or later.
CVE-2024-24581 affects all versions of OpenHarmony prior to 4.0.1.
CVE-2024-24581 is classified as a local privilege escalation vulnerability allowing arbitrary code execution.
CVE-2024-24581 requires local access to exploit, thus it cannot be exploited remotely.