Remote Code Execution Vulnerability in librtppayload.so Prior to SMR Oct-2024 Release 1
CVE-2024-34668

8.8HIGH

Key Information:

Vendor
Samsung
Vendor
CVE Published:
8 October 2024

Summary

The vulnerability arises from an out-of-bounds write flaw in the H.263 format parsing within librtppayload.so, which allows remote attackers to potentially execute arbitrary code with system privileges. To trigger this vulnerability, user interaction is required, creating a risk for users when handling specially crafted inputs that take advantage of this weakness. The issue affects various Samsung products using the affected versions of librtppayload.so and reveals the need for prompt updates to mitigate potential exploits.

Affected Version(s)

Samsung Mobile Devices SMR Oct-2024 Release in Android 12, 13, 14

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.