Buffer Overflow Vulnerability in Huawei Smartphone Camera Driver
CVE-2017-8180

7.8HIGH

Key Information:

Vendor
McAfee
Status
Vendor
CVE Published:
22 November 2017

Summary

The camera driver on MTK-platform Huawei smartphones is susceptible to a buffer overflow due to inadequate input validation. By exploiting this vulnerability, an attacker can persuade a user into installing a malicious app equipped with elevated privileges. This malicious application can then interact with the smartphone's driver using specially crafted parameters, potentially resulting in unauthorized privilege escalation and compromising the device's security. Proper software updates are crucial to mitigate this risk.

Affected Version(s)

Nice-AL00 Versions earlier than Nice-AL00C00B155

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.