PT-2018-18363 · Huawei · Huawei Mate 10
Mingjian Zhou
·
Publicado
2018-07-31
·
Atualizado
2018-10-04
·
CVE-2018-7993
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
HUAWEI Mate 10 smartphones versions prior to ALP-AL00 8.1.0.311
Description:
The issue is related to a use after free vulnerability on the mediaserver component. An attacker could trick the user into installing a malicious application, which causes the software to reference memory after it has been freed. This could potentially lead to the execution of arbitrary code.
Recommendations:
For versions prior to ALP-AL00 8.1.0.311, update to version ALP-AL00 8.1.0.311 or later to resolve the issue. As a temporary workaround, consider restricting the installation of applications from untrusted sources to minimize the risk of exploitation.
Correção
Use After Free
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Huawei Mate 10