
Cloud Vulnerability DB
A community-led vulnerabilities database
A use after free vulnerability exists in pub_crypto_recv_msg component prior to SMR Mar-2024 Release 1. The vulnerability is tracked as CVE-2024-20833 and was discovered in March 2024. The vulnerability affects Samsung Android devices running Android versions 11.0 and later (Samsung Mobile Security).
The vulnerability is caused by a race condition in pub_crypto_recv_msg that can lead to use-after-free memory corruption. The vulnerability has been assigned a CVSS v3.1 base score of 6.4 (Medium) with the vector string CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H by NIST NVD, while Samsung Mobile assigned it a score of 4.1 (Medium) with vector string CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N (NVD).
If exploited, this vulnerability allows local attackers with system privileges to cause memory corruption. The high complexity and requirement of system privileges limits the potential impact, though successful exploitation could lead to system compromise (NVD).
The vulnerability requires local access and system privileges to exploit. The high complexity of exploitation (AC:H) indicates that specific conditions need to be met for successful exploitation. There are no public reports of this vulnerability being exploited in the wild (NVD).
Samsung has released patches for this vulnerability as part of the March 2024 Security Maintenance Release (SMR Mar-2024 Release 1). Users should update their devices to the latest available security patch level to mitigate this vulnerability (Samsung Mobile Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."