CVE-2024-3759: Hmdfs has a use after free vulnerability
Published May 7, 2024
·Updated
in OpenHarmony v4.0.0 and prior versions allow a local attacker arbitrary code execution in TCB through use after free.
Affected Software
1 affected component
Openatom Openharmony<4.0.1
Event History
May 7, 2024
CVE Published
via MITRE·06:27 AM
Data Sourced
via MITRE·06:27 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-3759?
The severity of CVE-2024-3759 is high as it allows local attackers to execute arbitrary code in the Trusted Computing Base (TCB).
2
How do I fix CVE-2024-3759?
To fix CVE-2024-3759, upgrade OpenHarmony to version 4.0.1 or later to mitigate the use after free vulnerability.
3
What versions of OpenHarmony are affected by CVE-2024-3759?
CVE-2024-3759 affects OpenHarmony version 4.0.0 and all prior versions.
4
Who is affected by CVE-2024-3759?
Local attackers with access to the affected OpenHarmony versions can exploit CVE-2024-3759.
5
What type of vulnerability is CVE-2024-3759?
CVE-2024-3759 is classified as a use after free vulnerability, leading to arbitrary code execution.