First published: Tue May 07 2024(Updated: )
in OpenHarmony v4.0.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through use after free.
Credit: scy@openharmony.io
Affected Software | Affected Version | How to fix |
---|---|---|
Openatom Openharmony | <4.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-27217 is considered a critical vulnerability due to its potential for arbitrary code execution by local attackers.
To mitigate CVE-2024-27217, update OpenHarmony to version 4.0.1 or later, where the vulnerability has been addressed.
CVE-2024-27217 affects all users of OpenHarmony v4.0.0 and prior versions, as it allows local attackers to exploit the vulnerability in pre-installed apps.
Local attackers can exploit CVE-2024-27217 to gain arbitrary code execution in pre-installed applications.
Currently, there are no known workarounds for CVE-2024-27217, and users should prioritize updating to a fixed version.