Use-after-free in Samsung products - CVE-2024-44068

 

Use-after-free in Samsung products - CVE-2024-44068

Published: October 22, 2024


Vulnerability identifier: #VU99260
CSH Severity: High
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-44068
CWE-ID: CWE-416
Exploitation vector: Local access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a local application to escalate privileges on the system.

The vulnerability exists due to a use-after-free error in the mobile processor. A local application can execute arbitrary code with elevated privileges.

Note, the vulnerability is being actively exploited in the wild.


Affected software

Exynos 9820
Exynos 9825
Exynos 990
Exynos 980
Exynos 850
Exynos W920

How to mitigate CVE-2024-44068

Install updates from vendor's website.


External References

Related Security Bulletins