CVE-2024-45346

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Aug 28, 2024
Updated: Aug 29, 2024
CWE ID 94

Summary

CVE-2024-45346 identifies a code execution vulnerability in the XiaomiGetApps application, affecting various Xiaomi products. This vulnerability arises from a bypass in the verification logic, allowing attackers to execute arbitrary malicious code remotely without requiring elevated privileges. The exploit has a high base severity score of 8.8 and poses significant risks, including potential high impacts on confidentiality, integrity, and availability of affected systems. Remediation steps should include updating the XiaomiGetApps application to mitigate the risk. Organizations using the affected products should be particularly vigilant as exploitation could occur with minimal user interaction over a network.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share