First published: Mon Sep 02 2024(Updated: )
in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through use after free.
Credit: scy@openharmony.io
Affected Software | Affected Version | How to fix |
---|---|---|
Openatom Openharmony | <=4.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-41160 is considered a critical vulnerability as it allows local attackers to escalate permissions to root.
To mitigate CVE-2024-41160, update OpenHarmony to a version later than 4.1.0.
CVE-2024-41160 may lead to unauthorized access to sensitive information and system control through privilege escalation.
CVE-2024-41160 affects all users running OpenHarmony version 4.1.0 and prior releases.
CVE-2024-41160 is a local vulnerability that requires physical access or local credentials to exploit.