Heap Vulnerability in Samsung Mobile Processor Exynos Series
CVE-2024-27370

7.8HIGH

Key Information:

Vendor
Samsung
Vendor
CVE Published:
5 June 2024

Summary

An issue has been reported in Samsung’s mobile processors, specifically in the Exynos series, where a lack of input validation in the function handling configuration parameters can lead to unintended heap memory modifications. This flaw arises in the context of processing requests from userspace, potentially allowing an attacker to perform heap overwrite operations, thereby compromising system integrity and leading to unauthorized access or execution of arbitrary code.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.