Initiatives pour
En tant qu'autorité nationale en matière de cybersécurité, le CCB a développé plusieurs initiatives destinées à des publics spécifiques, qui sont présentées ici.
Reference:
Advisory #2024-249
Version:
1.0
Affected software:
m2m scaler driver in Samsung Mobile Processor and Wearable Processor Exynos 9820, 9825, 980, 990, 850, and W920
Type:
Use-After-Free leading to Privilege Escalation
CVE/CVSS:
CVE-2024-44068 :CVSS 8.1(CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
https://nvd.nist.gov/vuln/detail/CVE-2024-44068
A high Use-After-Free vulnerability has been disclosed in the a driver of several Samsung mobile processors. Exploiting this vulnerability can lead to privilege escalation and lets an attacker run arbitrary code with elevated privileges. It has been reported being actively exploited as a zero day by Google and it has a high impact on confidentiality, integrity and available.