Memory Corruption Vulnerability in WMI Can Be Exploited to Execute Arbitrary Code
CVE-2024-38410

7.8HIGH

Key Information:

Vendor

Qualcomm

Vendor
CVE Published:
4 November 2024

What is CVE-2024-38410?

A vulnerability exists in Qualcomm devices that can lead to memory corruption when the IOCLT is invoked while the device is in an invalid state. This issue arises due to the potential for the Windows Management Instrumentation (WMI) command buffer to be freed multiple times, which can compromise system stability and expose the device to various threats. Proper management of device states and improvements to buffer handling are necessary to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Snapdragon Snapdragon Compute FastConnect 6700

Snapdragon Snapdragon Compute FastConnect 6900

Snapdragon Snapdragon Compute FastConnect 7800

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.