Arbitrary Code Execution Vulnerability in libpadm.so's padmd_vld_qtbl
CVE-2024-20813
7.8HIGH
Summary
An out-of-bounds write vulnerability exists in the padmd_vld_qtbl component of libpadm.so, present in Samsung products before the SMR Feb-2024 Release 1. This flaw enables a local attacker to manipulate memory, potentially leading to arbitrary code execution. Exploiting this vulnerability can allow attackers to gain unauthorized access and control over affected systems. Ensuring timely updates and patches is crucial to maintain system integrity and security.
Affected Version(s)
Samsung Mobile Devices SMR Feb-2024 Release in Android 11, 12, 13, 14
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved