PT-2017-18159 · Google+1 · Android+2

Aravind Machiry

·

Published

2017-11-22

·

Updated

2017-12-08

·

CVE-2017-8150

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Huawei P10 versions before Victoria-L09AC605B162 Huawei P10 versions before Victoria-L29AC605B162 Huawei P10 Plus versions before Vicky-L29AC605B162
Description The issue is related to an arbitrary memory write vulnerability in the boot loaders of Huawei P10 and P10 Plus mobile phones. This vulnerability is caused by the lack of parameter validation. An attacker with root privilege of an Android system can trick a user into installing a malicious APP, which can modify specific data to cause arbitrary memory writing in the next system reboot. This can lead to continuous system reboot or arbitrary code execution.
Recommendations For Huawei P10 versions before Victoria-L09AC605B162, update to a version after Victoria-L09AC605B162 to resolve the issue. For Huawei P10 versions before Victoria-L29AC605B162, update to a version after Victoria-L29AC605B162 to resolve the issue. For Huawei P10 Plus versions before Vicky-L29AC605B162, update to a version after Vicky-L29AC605B162 to resolve the issue. As a temporary workaround, consider restricting the installation of APPs from untrusted sources to minimize the risk of exploitation.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-8150

Affected Products

Android
Huawei P10
Huawei P10 Plus