Privilege Escalation Vulnerability in Huawei Mate 9 Smartphones
CVE-2017-2707
7.1HIGH
Summary
The Mate 9 smartphones by Huawei are susceptible to a privilege escalation vulnerability through the Push module. This weakness allows attackers to manipulate rich media in messages, potentially leading to unauthorized message deletions or deception, where malicious actors can impersonate the user. By exploiting this flaw, an adversary can gain elevated privileges that compromise the integrity of message management on affected devices.
Affected Version(s)
Mate 9 MHA-AL00AC00B125
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved