Use-after-free in Samsung products - CVE-2024-44068
Published: October 22, 2024
Vulnerability identifier: #VU99260
CSH Severity: High
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-44068
CWE-ID: CWE-416
Exploitation vector: Local access
Exploit availability:
The vulnerability is being exploited in the wild
Vulnerability details
The vulnerability allows a local application to escalate privileges on the system.
The vulnerability exists due to a use-after-free error in the mobile processor. A local application can execute arbitrary code with elevated privileges.
Note, the vulnerability is being actively exploited in the wild.
Affected software
Exynos 9820
Exynos 9825
Exynos 990
Exynos 980
Exynos 850
Exynos W920
Exynos 9825
Exynos 990
Exynos 980
Exynos 850
Exynos W920
How to mitigate CVE-2024-44068
Install updates from vendor's website.