Initiativen für
Als nationale Behörde für Cybersicherheit hat das ZCB mehrere Initiativen für bestimmte Zielgruppen entwickelt, die hier vorgestellt werden.
Reference:
Advisory #2024-249
Version:
1.0
Affected software:
m2m scaler driver in Samsung Mobile Processor and Wearable Processor Exynos 9820, 9825, 980, 990, 850, and W920
Type:
Use-After-Free leading to Privilege Escalation
CVE/CVSS:
CVE-2024-44068 :CVSS 8.1(CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
https://nvd.nist.gov/vuln/detail/CVE-2024-44068
A high Use-After-Free vulnerability has been disclosed in the a driver of several Samsung mobile processors. Exploiting this vulnerability can lead to privilege escalation and lets an attacker run arbitrary code with elevated privileges. It has been reported being actively exploited as a zero day by Google and it has a high impact on confidentiality, integrity and available.