Remote Code Execution Vulnerability in Trusted Firmware-M by Trusted Firmware
CVE-2024-45746

Currently unrated

Key Information:

Vendor
CVE Published:
9 October 2024

What is CVE-2024-45746?

A vulnerability in Trusted Firmware-M allows attackers to exploit unvalidated pointers in user-controlled mailbox messages. The vulnerability arises from unchecked pointers to input and output argument lists. Following a PSA call, the output argument length is modified without proper validation. This flaw enables unauthorized writing within secure firmware memory, potentially allowing attackers to hijack control flow and execute arbitrary code remotely.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

EPSS Score

6% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

.