Remote Code Execution Vulnerability in librtppayload.so Prior to SMR Oct-2024 Release 1
CVE-2024-34668
8.8HIGH
Summary
The vulnerability arises from an out-of-bounds write flaw in the H.263 format parsing within librtppayload.so, which allows remote attackers to potentially execute arbitrary code with system privileges. To trigger this vulnerability, user interaction is required, creating a risk for users when handling specially crafted inputs that take advantage of this weakness. The issue affects various Samsung products using the affected versions of librtppayload.so and reveals the need for prompt updates to mitigate potential exploits.
Affected Version(s)
Samsung Mobile Devices SMR Oct-2024 Release in Android 12, 13, 14
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved