Skip to content
COOEY

EXPOSURES › CVE-2024-43047

CVE-2024-43047

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-10-08 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2024-43047 ↗
⌖ EXPLOITED IN THE WILD SHAME 65/100 exploited-in-wildsupply-chainunpatched

Qualcomm chipsets contain a use-after-free vulnerability in DSP Services that is actively exploited in the wild.

This use-after-free vulnerability in Qualcomm chipsets allows memory corruption in DSP Services while maintaining HLOS memory maps, creating a significant supply-chain risk for DIB organizations relying on these components. Because the vulnerability is actively exploited and linked to ransomware campaigns, vendors must prioritize patching and customers should verify firmware integrity immediately.

Shame score — Active exploitation of a known vulnerability in widely deployed hardware components indicates a failure in timely patching and supply-chain security.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Multiple Qualcomm chipsets contain a use-after-free vulnerability due to memory corruption in DSP Services while maintaining memory maps of HLOS memory.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.