VDB
CVE-2024-20833
CVE-2024-20833
PUBLISHED
CVSS 4.099999904632568 MEDIUM
Use after free vulnerability in pub_crypto_recv_msg prior to SMR Mar-2024 Release 1 due to race condition allows local attackers with system privilege to cause memory corruption.
EPSS 0.11% · 1.3th percentile
Risk Scores
CVSS 3.1
4.099999904632568
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N
EPSS Score
0.11%
1.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| samsung | android | 11.0, 11.0, 11.0 |
| Samsung Mobile | Samsung Mobile Devices | *, SMR Mar-2024 Release in Android 11, 12, 13, 14 |
Timeline
- Mar 5, 2024 CVE Published
- Mar 5, 2024 PoC Published
- Mar 5, 2024 PoC Published
- Mar 6, 2024 EPSS Score
- Apr 1, 2024 EPSS Score
- Apr 28, 2024 EPSS Score
- May 24, 2024 EPSS Score
- Jun 20, 2024 EPSS Score
- Jul 16, 2024 EPSS Score
- Aug 11, 2024 EPSS Score
- Sep 7, 2024 EPSS Score
- Oct 3, 2024 EPSS Score