Cross-process screen stack vulnerability may compromise service confidentiality
CVE-2024-54112

5.5MEDIUM

Key Information:

Vendor

Huawei

Status
Vendor
CVE Published:
12 December 2024

What is CVE-2024-54112?

The cross-process screen stack vulnerability present in the UIExtension module of Huawei's products exposes serious risks related to service confidentiality. By exploiting this vulnerability, an attacker could manipulate the screen stack across different processes, potentially allowing unauthorized access to sensitive information. As organizations increasingly rely on these products for their operations, the importance of addressing this vulnerability cannot be overstated, as it highlights the critical need for proactive security measures in the deployment and management of affected services.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

HarmonyOS 5.0.0

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

.