CVE-2017-2699
The Huawei Themes APP in versions earlier than PLK-UL00C17B385, versions earlier than CRR-L09C432B380, versions earlier than LYO-L21C577B128 has a privilege elevation vulnerability.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.97%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The Huawei Themes APP in versions earlier than PLK-UL00C17B385, versions earlier than CRR-L09C432B380, versions earlier than LYO-L21C577B128 has a privilege elevation vulnerability. An attacker could exploit this vulnerability to upload theme packs containing malicious files and trick users into installing the theme packets, resulting in the execution of arbitrary code.
- CVSS 3.0
- 7.8 HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 0.97% probability · 60th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-434
- Affected
- huawei/honor 7 firmware · huawei/mate s firmware · huawei/lyo-l21 firmware
- Source
- psirt@huawei.com
References
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20170222-01-theme-enVendor Advisory
- http://www.securityfocus.com/bid/96424Third Party Advisory, VDB Entry
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20170222-01-theme-enVendor Advisory
- http://www.securityfocus.com/bid/96424Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.