VDB
CVE-2024-44068
CVE-2024-44068
PUBLISHED
Es besteht eine Schwachstelle in Samsung Exynos aufgrund von Use-After-Free in den mobilen Prozessoren. Ein Angreifer kann diese Schwachstelle ausnutzen, um erweiterte Rechte zu erlangen.
EPSS 0.71% · 72.7th percentile
Risk Scores
EPSS Score
0.71%
72.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Samsung | Samsung Exynos 9825 | |
| Samsung | Samsung Exynos 850 | |
| Samsung | Samsung Android 14 | |
| Samsung | Samsung Exynos 980 | |
| Samsung | Samsung Android 13 | |
| Samsung | Samsung Exynos 9820 | |
| Samsung | Samsung Exynos W920 | |
| Samsung | Samsung Android 12 | |
| Samsung | Samsung Exynos 990 |
Timeline
- Oct 6, 2024 CVE Published
- Oct 7, 2024 PoC Published
- Oct 8, 2024 EPSS Score
- Oct 14, 2024 Coalition ESS Score
- Oct 22, 2024 Coalition ESS Score
- Oct 22, 2024 CVE Updated
- Oct 27, 2024 EPSS Score
- Nov 15, 2024 EPSS Score
- Dec 5, 2024 EPSS Score
- Dec 23, 2024 EPSS Score
- Jan 11, 2025 EPSS Score
- Jan 30, 2025 EPSS Score
References
- https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-3091.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-3091 advisory
- https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2024-44068/ advisory
- https://googleprojectzero.github.io/0days-in-the-wild/0day-RCAs/2024/CVE-2024-44068.html advisory
- https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-3095.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-3095 advisory
- https://security.samsungmobile.com/securityUpdate.smsb advisory