CVE-2024-28951: Arkcompiler runtime has a use after free vulnerability
Published Apr 2, 2024
·Updated
in OpenHarmony v4.0.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through use after free.
Affected Software
2 affected components
OpenHarmony OpenHarmony<4.0.0
Openatom Openharmony=4.0
Event History
Apr 2, 2024
CVE Published
via MITRE·06:23 AM
Data Sourced
via MITRE·06:23 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-28951?
CVE-2024-28951 is considered to have a high severity due to its potential for allowing arbitrary code execution.
2
How do I fix CVE-2024-28951?
To mitigate CVE-2024-28951, upgrade OpenHarmony to version 4.0.1 or later where the vulnerability is patched.
3
Who is affected by CVE-2024-28951?
CVE-2024-28951 affects local users of OpenHarmony versions up to 4.0.0 who can exploit pre-installed applications.
4
What causes CVE-2024-28951?
CVE-2024-28951 is caused by a use-after-free vulnerability in OpenHarmony that allows for arbitrary code execution.
5
Is CVE-2024-28951 remotely exploitable?
No, CVE-2024-28951 requires local access to exploit, making it less of a remote threat.