EXPOSURES › CVE-2024-43047
CVE-2024-43047
HIGH ⌖ ON CISA KEV · EXPLOITEDQualcomm chipsets contain a use-after-free vulnerability in DSP Services that is actively exploited in the wild.
This use-after-free vulnerability in Qualcomm chipsets allows memory corruption in DSP Services while maintaining HLOS memory maps, creating a significant supply-chain risk for DIB organizations relying on these components. Because the vulnerability is actively exploited and linked to ransomware campaigns, vendors must prioritize patching and customers should verify firmware integrity immediately.
Shame score — Active exploitation of a known vulnerability in widely deployed hardware components indicates a failure in timely patching and supply-chain security.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Multiple Qualcomm chipsets contain a use-after-free vulnerability due to memory corruption in DSP Services while maintaining memory maps of HLOS memory.