Integer Overflow Vulnerability in Huawei Honor 9 Smartphone
CVE-2017-8205

7.8HIGH

Key Information:

Vendor
McAfee
Status
Vendor
CVE Published:
22 November 2017

Summary

The Bastet driver within Huawei's Honor 9 smartphones exhibits an integer overflow vulnerability due to insufficient parameter validation in certain software versions. This flaw can be exploited by an attacker who lures users into installing a malicious application that gains root privileges. Once the app is installed, it can send specially crafted parameters to the smartphone's driver, enabling the execution of arbitrary code, potentially compromising the device's security.

Affected Version(s)

Honor 9 Versions earlier than Stanford-AL10C00B175

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.