PT-2018-18363 · Huawei · Huawei Mate 10

Mingjian Zhou

·

Publicado

2018-07-31

·

Atualizado

2018-10-04

·

CVE-2018-7993

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: HUAWEI Mate 10 smartphones versions prior to ALP-AL00 8.1.0.311
Description: The issue is related to a use after free vulnerability on the mediaserver component. An attacker could trick the user into installing a malicious application, which causes the software to reference memory after it has been freed. This could potentially lead to the execution of arbitrary code.
Recommendations: For versions prior to ALP-AL00 8.1.0.311, update to version ALP-AL00 8.1.0.311 or later to resolve the issue. As a temporary workaround, consider restricting the installation of applications from untrusted sources to minimize the risk of exploitation.

Correção

Use After Free

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-7993

Produtos afetados

Huawei Mate 10