PT-2018-6430 · Huawei · Huawei Mate 9 Pro

Published

2018-06-14

·

Updated

2018-08-13

·

CVE-2017-17173

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Huawei Mate 9 Pro versions prior to LON-AL00B 8.0.0.356(C00)
Description: The issue is related to insufficient parameters verification in the GPU driver, which can lead to an arbitrary memory free vulnerability. An attacker can trick a user into installing a malicious application and send specific parameters to the driver to release special kernel memory resources. This could result in a phone crash or potentially allow for arbitrary code execution.
Recommendations: For versions prior to LON-AL00B 8.0.0.356(C00), update to version LON-AL00B 8.0.0.356(C00) or later to resolve the issue. As a temporary workaround, consider restricting the installation of applications from untrusted sources to minimize the risk of exploitation.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-17173

Affected Products

Huawei Mate 9 Pro