CVE-2024-36260: Arkcompiler Ets Runtime has an out-of-bounds write vulnerability
Published Jul 2, 2024
·Updated
in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through out-of-bounds write.
Affected Software
1 affected component
Openatom Openharmony<=4.0
Event History
Jul 2, 2024
CVE Published
via MITRE·08:13 AM
Data Sourced
via MITRE·08:13 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-36260?
CVE-2024-36260 is considered a critical vulnerability due to its potential for arbitrary code execution.
2
How do I fix CVE-2024-36260?
To fix CVE-2024-36260, upgrade to a version of OpenHarmony later than v4.0.0.
3
What kind of impact does CVE-2024-36260 have on affected systems?
CVE-2024-36260 allows a remote attacker to execute arbitrary code in pre-installed applications.
4
Which versions of OpenHarmony are affected by CVE-2024-36260?
CVE-2024-36260 affects OpenHarmony v4.0.0 and all prior versions.
5
Who can exploit CVE-2024-36260?
CVE-2024-36260 can be exploited by remote attackers with no authentication required.