CVE-2024-0039
CRITICALAndroid - Out-of-bounds Write in Bluetooth ATT Protocol
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2024-0039. PoCs published by 41yn14.
AI-analyzed exploit summary This repository contains a functional Python exploit for CVE-2024-0039, which targets an Android vulnerability to achieve remote code execution via a malicious MP4 file. The exploit includes a ROP chain and reverse shell payload, with logging and unit tests for validation.
Description
In attp_build_value_cmd of att_protocol.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
Exploits (1)
This repository contains a functional Python exploit for CVE-2024-0039, which targets an Android vulnerability to achieve remote code execution via a malicious MP4 file. The exploit includes a ROP chain and reverse shell payload, with logging and unit tests for validation.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H