CVE-2024-37030: Arkcompiler Ets Runtime has a use after free vulnerability
Published Jul 2, 2024
·Updated
in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through use after free.
Affected Software
1 affected component
Openatom Openharmony<=4.0
Event History
Jul 2, 2024
CVE Published
via MITRE·08:13 AM
Data Sourced
via MITRE·08:13 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-37030?
CVE-2024-37030 is classified as a critical vulnerability due to the potential for arbitrary code execution.
2
How do I fix CVE-2024-37030?
To fix CVE-2024-37030, update to the latest version of OpenHarmony that mitigates this vulnerability.
3
What versions of OpenHarmony are affected by CVE-2024-37030?
OpenHarmony v4.0.0 and prior versions are affected by CVE-2024-37030.
4
What impact does CVE-2024-37030 have on pre-installed apps?
CVE-2024-37030 allows remote attackers to execute arbitrary code within pre-installed apps.
5
Who is vulnerable to CVE-2024-37030?
Any user running OpenHarmony v4.0.0 or earlier versions is vulnerable to CVE-2024-37030.