CVE-2024-27217: MSDP has a use after free vulnerability
in OpenHarmony v4.0.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through use after free.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-27217?
CVE-2024-27217 is considered a critical vulnerability due to its potential for arbitrary code execution by local attackers.
How do I fix CVE-2024-27217?
To mitigate CVE-2024-27217, update OpenHarmony to version 4.0.1 or later, where the vulnerability has been addressed.
Who is affected by CVE-2024-27217?
CVE-2024-27217 affects all users of OpenHarmony v4.0.0 and prior versions, as it allows local attackers to exploit the vulnerability in pre-installed apps.
What types of attacks can exploit CVE-2024-27217?
Local attackers can exploit CVE-2024-27217 to gain arbitrary code execution in pre-installed applications.
Is there a workaround for CVE-2024-27217 while awaiting a fix?
Currently, there are no known workarounds for CVE-2024-27217, and users should prioritize updating to a fixed version.