Privilege Escalation Vulnerability in Huawei Mate 9 Smartphones
CVE-2017-2707

7.1HIGH

Key Information:

Vendor
McAfee
Status
Vendor
CVE Published:
22 November 2017

Summary

The Mate 9 smartphones by Huawei are susceptible to a privilege escalation vulnerability through the Push module. This weakness allows attackers to manipulate rich media in messages, potentially leading to unauthorized message deletions or deception, where malicious actors can impersonate the user. By exploiting this flaw, an adversary can gain elevated privileges that compromise the integrity of message management on affected devices.

Affected Version(s)

Mate 9 MHA-AL00AC00B125

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.