CVE-2024-39831: AccessTokenManager has an use after free vulnerability
Published Oct 8, 2024
·Updated
in OpenHarmony v4.1.0 allow a local attacker with high privileges arbitrary code execution in pre-installed apps through use after free.
Affected Software
1 affected component
Openatom Openharmony<=4.1.0
Event History
Oct 8, 2024
CVE Published
via MITRE·03:03 AM
Data Sourced
via MITRE·03:03 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-39831?
CVE-2024-39831 is classified as a high severity vulnerability due to its potential for arbitrary code execution.
2
What types of attacks are possible with CVE-2024-39831?
CVE-2024-39831 allows a local attacker with high privileges to execute arbitrary code in pre-installed apps.
3
How do I fix CVE-2024-39831?
To fix CVE-2024-39831, users should upgrade OpenHarmony to a version beyond 4.1.0.
4
Who is affected by CVE-2024-39831?
CVE-2024-39831 affects all users of OpenHarmony version 4.1.0 and prior who have high privileges.
5
What can be done to mitigate CVE-2024-39831?
Mitigation steps for CVE-2024-39831 include ensuring that applications run with the least privileges necessary.