Huawei · Huawei Hisuite · CVE-2016-5821
**Name of the Vulnerable Software and Affected Versions**
Huawei HiSuite versions prior to 4.0.4.204 ove (Out of China)
Huawei HiSuite versions prior to 4.0.4.301 (China)
**Description**
The issue allows local users to gain SYSTEM privileges via a Trojan horse `SspiCli.dll` or `USERENV.dll` file or possibly other unspecified DLL files, due to a weak ACL for the HiSuite service directory.
**Recommendations**
For versions prior to 4.0.4.204 ove (Out of China), update to version 4.0.4.204 ove or later.
For versions prior to 4.0.4.301 (China), update to version 4.0.4.301 or later.