Use of Out-of-range Pointer Offset in Qualcomm products - CVE-2024-45573
Published: February 3, 2025
Vulnerability identifier: #VU103520
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-45573
CWE-ID: CWE-823
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local application to execute arbitrary code.
The vulnerability exists due to improper input validation in Display. A local application can execute arbitrary code.
Affected software
Snapdragon 8cx Gen 3 Compute Platform (SC8280XP-AB
WSA8845H
WSA8845
WSA8840
WSA8835
WSA8830
WCN3660B
WCN3620
WCD9385
WCD9380
WCD9375
WCD9370
BB)
FastConnect 6700
Snapdragon 7c+ Gen 3 Compute
Snapdragon 429 Mobile Platform
SC8380XP
Qualcomm Video Collaboration VC3 Platform
QCS6490
QCS5430
QCM6490
QCM5430
FastConnect 7800
FastConnect 6900
SDM429W
WSA8845H
WSA8845
WSA8840
WSA8835
WSA8830
WCN3660B
WCN3620
WCD9385
WCD9380
WCD9375
WCD9370
BB)
FastConnect 6700
Snapdragon 7c+ Gen 3 Compute
Snapdragon 429 Mobile Platform
SC8380XP
Qualcomm Video Collaboration VC3 Platform
QCS6490
QCS5430
QCM6490
QCM5430
FastConnect 7800
FastConnect 6900
SDM429W
How to mitigate CVE-2024-45573
Install security update from vendor's website.