Remotely Exploitable Out-of-Bounds Write Vulnerability in librtppayload.so Prior to SMR Oct-2024 Release 1
CVE-2024-34667

8.8HIGH

Key Information:

Vendor
Samsung
Vendor
CVE Published:
8 October 2024

Summary

An out-of-bounds write vulnerability has been identified in the H.265 parsing functionality of Samsung's librtppayload.so. This flaw allows remote attackers to exploit the vulnerability and execute arbitrary code with system privileges, provided that user interaction occurs to trigger the attack. Systems affected are those running versions prior to the SMR October 2024 Release 1. It is crucial for users and administrators of affected systems to apply available security updates promptly to mitigate potential risks associated with this vulnerability.

Affected Version(s)

Samsung Mobile Devices SMR Oct-2024 Release in Android 12, 13, 14

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.