Remote Execution of Arbitrary Code with System Privileges Through Out-of-Bounds Write in librtppayload.so Prior to SMR Oct-2024 Release 1
CVE-2024-34669

8.8HIGH

Key Information:

Vendor
Samsung
Vendor
CVE Published:
8 October 2024

Summary

An out-of-bounds write vulnerability exists in the parsing of H.263+ format within the librtppayload.so library used in Samsung products. This flaw allows remote attackers to execute arbitrary code with system privileges upon user interaction, leading to potentially severe security implications. The vulnerability affects versions of the librtppayload.so library prior to the SMR Oct-2024 Release 1. Users are advised to stay informed about updates and exercise caution to mitigate the risks associated with this vulnerability.

Affected Version(s)

Samsung Mobile Devices SMR Oct-2024 Release in Android 12, 13, 14

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.